Amd
amd
288 CVEs • 1,690 products
Products (1,690)
Click to collapseToggle
Products (1,690)
Click to collapse
CVEs (288)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Amd 66Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+63 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures l...Show more |
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of...Show more |
1Amd 40Epyc 7232p Firmware Epyc 7251 FirmwareEpyc 7252 Firmware+37 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of ser...Show more |
1Amd 23Epyc 72f3 Firmware Epyc 7313 FirmwareEpyc 7313p Firmware+20 moreJun 17, 2026 May 9, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 Insufficient address validation, may allow an
attacker with a compromised ABL and UApp to corrupt sensitive memory locations
potentially resulting in a loss of integrity or availability.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Insufficient input validation of mailbox data in the
SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially
leading to a loss of integrity and privilege escalation.
|
1Amd 128Amd 3015ce Firmware Amd 3015e FirmwareEpyc 7001 Firmware+125 moreJun 17, 2026 May 9, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to information disclosure.
|
1Amd 54Amd 3015ce Firmware Amd 3015e FirmwareRyzen 3 2200g Firmware+51 moreJun 17, 2026 May 9, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents...Show more |
1Amd 98Epyc 7001 Firmware Epyc 7002 FirmwareEpyc 7232p Firmware+95 moreJun 17, 2026 May 9, 2023 N/A· v4 7.4 HIGH· v3 N/A· v2 A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.
|
1Amd 152Amd 3015ce Firmware Amd 3015e FirmwareEpyc 7002 Firmware+149 moreJun 17, 2026 May 9, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised ABL which may cause
arbitrary memory values to be initialized to zero, potentially leading to a
loss of integrity.
|
1Amd 89Athlon Gold 3150u Firmware Athlon Silver 3050u FirmwareRyzen 3 2200u Firmware+86 moreJun 17, 2026 Apr 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
|
1Amd 89Athlon Gold 3150u Firmware Athlon Silver 3050u FirmwareRyzen 3 2200u Firmware+86 moreJun 17, 2026 Apr 2, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
|
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged us...Show more |
1Amd 165A10 9600p Firmware A10 9630p FirmwareA12 9700p Firmware+162 moreJun 17, 2026 Mar 1, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 When SMT is enabled, certain AMD processors may speculatively execute instructions using a target
from the sibling thread after an SMT mode switch potentially resulting in information disclosure. |
1Amd 50Epyc 7002 Firmware Epyc 7003 FirmwareEpyc 7232p Firmware+47 moreJun 17, 2026 Jan 11, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
|
1Amd 50Epyc 7002 Firmware Epyc 7003 FirmwareEpyc 7232p Firmware+47 moreJun 17, 2026 Jan 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
|
1Amd 24Epyc 7003 Firmware Epyc 72f3 FirmwareEpyc 7313 Firmware+21 moreJun 17, 2026 Jan 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
|
1Amd 50Epyc 7002 Firmware Epyc 7003 FirmwareEpyc 7232p Firmware+47 moreJun 17, 2026 Jan 11, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
|
1Amd 50Epyc 7002 Firmware Epyc 7003 FirmwareEpyc 7232p Firmware+47 moreJun 17, 2026 Jan 11, 2023 N/A· v4 2.4 LOW· v3 N/A· v2 Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
|
1Amd 64Epyc 7001 Firmware Epyc 7002 FirmwareEpyc 7003 Firmware+61 moreJun 17, 2026 Jan 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
|
1Amd 50Epyc 7002 Firmware Epyc 7003 FirmwareEpyc 7232p Firmware+47 moreJun 17, 2026 Jan 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
|