Amd
amd
288 CVEs • 1,690 products
Products (1,690)
Click to collapseToggle
Products (1,690)
Click to collapse
CVEs (288)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Amd 119Athlon 3015ce Firmware Athlon 3015e FirmwareAthlon Gold 3150c Firmware+116 moreJun 17, 2026 Aug 8, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM....Show more |
3Amd DebianXen71Athlon Gold 7220u Firmware Debian LinuxEpyc 7232p Firmware+68 moreJun 17, 2026 Jul 24, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. |
1Amd 88Epyc 5552 Firmware Epyc 7232p FirmwareEpyc 7251 Firmware+85 moreJun 17, 2026 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resultin...Show more |
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of...Show more |
1Amd 55Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+52 moreJun 17, 2026 May 9, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event pot...Show more |
1Amd 63Ryzen 1200 (af) Firmware Ryzen 1600 (af) FirmwareRyzen 2200g Firmware+60 moreJun 17, 2026 May 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient input validation in ABL may enable
a privileged attacker to corrupt ASP memory, potentially resulting in a loss of
integrity or code execution.
|
1Amd 44Ryzen 3100 Firmware Ryzen 3300x FirmwareRyzen 3500 Firmware+41 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient input validation in ASP may allow
an attacker with a compromised SMM to induce out-of-bounds memory reads within
the ASP, potentially leading to a denial of service.
|
1Amd 7Ryzen 3945wx Firmware Ryzen 3955wx FirmwareRyzen 3960x Firmware+4 moreJun 17, 2026 May 9, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achi...Show more |
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure P...Show more |
1Amd 63Epyc 7232p Firmware Epyc 7251 FirmwareEpyc 7252 Firmware+60 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in...Show more |
1Amd 23Ryzen 3100 Firmware Ryzen 3300x FirmwareRyzen 3500 Firmware+20 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of se...Show more |
1Amd 56Athlon Gold 3150g Firmware Athlon Gold 3150ge FirmwareAthlon Silver 3050ge Firmware+53 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management U...Show more |
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An attacker with a compromised ASP could
possibly send malformed commands to an ASP on another CPU, resulting in an out
of bounds write, potentially leading to a loss a loss of integrity.
|
1Amd 63Epyc 7232p Firmware Epyc 7251 FirmwareEpyc 7252 Firmware+60 moreJun 17, 2026 May 9, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Improper access control settings in ASP
Bootloader may allow an attacker to corrupt the return address causing a
stack-based buffer overrun potentially leading to arbitrary code execution.
|
1Amd 23Epyc 72f3 Firmware Epyc 7313 FirmwareEpyc 7313p Firmware+20 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient input validation on the model
specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest
memory integrity.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Improper input validation in ABL may enable an
attacker with physical access, to perform arbitrary memory overwrites,
potentially leading to a loss of integrity and code execution.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 Insufficient syscall input validation in the ASP
Bootloader may allow a privileged attacker to execute arbitrary DMA copies,
which can lead to code execution.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper validation of DRAM addresses in SMU may
allow an attacker to overwrite sensitive memory locations within the ASP
potentially resulting in a denial of service.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Insufficient input validation in the SMU may
enable a privileged attacker to write beyond the intended bounds of a shared
memory buffer potentially leading to a loss of integrity.
|
1Amd 48Epyc 7232p Firmware Epyc 7252 FirmwareEpyc 7262 Firmware+45 moreJun 17, 2026 May 9, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Insufficient input validation in the SMU may
allow an attacker to corrupt SMU SRAM potentially leading to a loss of
integrity or denial of service. |