CVEs (35)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Amd 85Epyc 7203 Firmware Epyc 7203p FirmwareEpyc 7232p Firmware+82 moreNov 21, 2024 Nov 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service. |
1Amd 108Athlon 3015ce Firmware Athlon 3015e FirmwareRyzen 3 3100 Firmware+105 moreNov 21, 2024 Nov 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
|
1Amd 105Athlon 3015ce Firmware Athlon 3015e FirmwareRyzen 3 3100 Firmware+102 moreNov 21, 2024 Nov 14, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Failure to validate the AMD SMM communication buffer
may allow an attacker to corrupt the SMRAM potentially leading to arbitrary
code execution. |
1Amd 137Epyc 7001 Firmware Epyc 7203 FirmwareEpyc 7203p Firmware+134 moreNov 21, 2024 Nov 14, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service. |
1Amd 101Ryzen 3100 Firmware Ryzen 3300x FirmwareRyzen 3500 Firmware+98 moreJun 27, 2025 Sep 20, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
1Amd 125Epyc 7003 Firmware Epyc 72f3 FirmwareEpyc 7313 Firmware+122 moreJun 27, 2025 Sep 20, 2023 N/A· v4 4.4 MEDIUM· v3 N/A· v2 Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
1Amd 1224700s Firmware Athlon Gold 3150c FirmwareAthlon Gold 3150g Firmware+119 moreNov 21, 2024 Aug 8, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary cod...Show more |
3Amd DebianXen71Athlon Gold 7220u Firmware Debian LinuxEpyc 7232p Firmware+68 moreFeb 13, 2025 Jul 24, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. |
1Amd 128Amd 3015ce Firmware Amd 3015e FirmwareEpyc 7001 Firmware+125 moreJan 28, 2025 May 9, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to information disclosure.
|
1Amd 98Epyc 7001 Firmware Epyc 7002 FirmwareEpyc 7232p Firmware+95 moreJan 28, 2025 May 9, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.
|
1Amd 152Amd 3015ce Firmware Amd 3015e FirmwareEpyc 7002 Firmware+149 moreJan 28, 2025 May 9, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised ABL which may cause
arbitrary memory values to be initialized to zero, potentially leading to a
loss of integrity.
|
1Amd 89Athlon Gold 3150u Firmware Athlon Silver 3050u FirmwareRyzen 3 2200u Firmware+86 moreFeb 25, 2025 Apr 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
|
1Amd 89Athlon Gold 3150u Firmware Athlon Silver 3050u FirmwareRyzen 3 2200u Firmware+86 moreFeb 20, 2025 Apr 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
|
1Amd 165A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+162 moreApr 13, 2026 Mar 1, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 When SMT is enabled, certain AMD processors may speculatively execute instructions using a target
from the sibling thread after an SMT mode switch potentially resulting in information disclosure. |
3Amd FedoraprojectXen169A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+166 moreNov 21, 2024 Nov 9, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. |
1Amd 103Amd 3015ce Firmware Amd 3015e FirmwareAmd 3020e Firmware+100 moreNov 21, 2024 Nov 9, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA. |
1Amd 101Amd 3015ce Firmware Amd 3015e FirmwareAmd 3020e Firmware+98 moreNov 21, 2024 Nov 9, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. |
1Amd 103Amd 3015ce Firmware Amd 3015e FirmwareAmd 3020e Firmware+100 moreNov 21, 2024 Nov 9, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. |
1Amd 179Athlon 3050ge Firmware Athlon 3150g FirmwareAthlon 3150ge Firmware+176 moreNov 21, 2024 Aug 10, 2022 N/A· v4 5.6 MEDIUM· v3 N/A· v2 Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the content...Show more |
4Amd DebianFedoraproject+1 more126A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+123 moreNov 21, 2024 Jul 14, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. |