← Back

Amd

amd

288 CVEs • 1,690 products

Products (1,690)

Click to collapse
Toggle

CVEs (288)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Amd
66Athlon Gold 3150g Firmware
Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+63 more
Jun 17, 2026
May 9, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures l...Show more
Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity. Show less
1Amd
56Athlon Gold 3150g Firmware
Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of...Show more
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service. Show less
1Amd
40Epyc 7232p Firmware
Epyc 7251 FirmwareEpyc 7252 Firmware+37 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of ser...Show more
Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service. Show less
1Amd
23Epyc 72f3 Firmware
Epyc 7313 FirmwareEpyc 7313p Firmware+20 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.1 HIGH· v3
N/A· v2
Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.
1Amd
48Epyc 7232p Firmware
Epyc 7252 FirmwareEpyc 7262 Firmware+45 more
Jun 17, 2026
May 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.
1Amd
128Amd 3015ce Firmware
Amd 3015e FirmwareEpyc 7001 Firmware+125 more
Jun 17, 2026
May 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
1Amd
54Amd 3015ce Firmware
Amd 3015e FirmwareRyzen 3 2200g Firmware+51 more
Jun 17, 2026
May 9, 2023
N/A· v4
8.2 HIGH· v3
N/A· v2
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents...Show more
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents. Show less
1Amd
98Epyc 7001 Firmware
Epyc 7002 FirmwareEpyc 7232p Firmware+95 more
Jun 17, 2026
May 9, 2023
N/A· v4
7.4 HIGH· v3
N/A· v2
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
1Amd
152Amd 3015ce Firmware
Amd 3015e FirmwareEpyc 7002 Firmware+149 more
Jun 17, 2026
May 9, 2023
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
1Amd
89Athlon Gold 3150u Firmware
Athlon Silver 3050u FirmwareRyzen 3 2200u Firmware+86 more
Jun 17, 2026
Apr 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
1Amd
89Athlon Gold 3150u Firmware
Athlon Silver 3050u FirmwareRyzen 3 2200u Firmware+86 more
Jun 17, 2026
Apr 2, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
1Amd
1Ryzen Master
Jun 17, 2026
Mar 1, 2023
N/A· v4
7.8 HIGH· v3
N/A· v2
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged us...Show more
Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user. Show less
1Amd
165A10 9600p Firmware
A10 9630p FirmwareA12 9700p Firmware+162 more
Jun 17, 2026
Mar 1, 2023
N/A· v4
4.7 MEDIUM· v3
N/A· v2
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
1Amd
50Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+47 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
1Amd
50Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+47 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
1Amd
24Epyc 7003 Firmware
Epyc 72f3 FirmwareEpyc 7313 Firmware+21 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
1Amd
50Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+47 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
1Amd
50Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+47 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
2.4 LOW· v3
N/A· v2
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
1Amd
64Epyc 7001 Firmware
Epyc 7002 FirmwareEpyc 7003 Firmware+61 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
1Amd
50Epyc 7002 Firmware
Epyc 7003 FirmwareEpyc 7232p Firmware+47 more
Jun 17, 2026
Jan 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.