VYPR

AGESA

by AMD

CVEs (3)

  • CVE-2023-20576HigSep 2, 2026
    risk 0.50cvss 7.7epss 0.00

    Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.

  • CVE-2020-12890MedDec 10, 2021
    risk 0.44cvss 6.7epss 0.00

    Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by…

  • CVE-2024-21970MedSep 6, 2025
    risk 0.29cvss 4.4epss 0.00

    Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.