ASP
by AMD
CVEs (6)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46765 | Hig | 0.49 | 7.5 | 0.01 | May 9, 2023 | Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service. | ||
| CVE-2023-20522 | Hig | 0.49 | 7.5 | 0.01 | Jan 11, 2023 | Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service. | ||
| CVE-2023-20523 | Med | 0.37 | 5.7 | 0.00 | Jan 11, 2023 | TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service. | ||
| CVE-2021-26354 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity. | ||
| CVE-2023-20508 | Med | 0.33 | 5.0 | 0.00 | Feb 12, 2025 | Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, potentially leading to loss of confidentiality, integrity, or availability. | ||
| CVE-2023-20507 | Low | 0.15 | 2.3 | 0.00 | Feb 11, 2025 | An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data integrity. |
- risk 0.49cvss 7.5epss 0.01
Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service.
- risk 0.49cvss 7.5epss 0.01
Insufficient input validation in ASP may allow an attacker with a malicious BIOS to potentially cause a denial of service.
- risk 0.37cvss 5.7epss 0.00
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.
- risk 0.36cvss 5.5epss 0.00
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
- risk 0.33cvss 5.0epss 0.00
Improper access control in the ASP could allow a privileged attacker to perform an out-of-bounds write to a memory location not controlled by the attacker, potentially leading to loss of confidentiality, integrity, or availability.
- risk 0.15cvss 2.3epss 0.00
An integer overflow in the ASP could allow a privileged attacker to perform an out-of-bounds write, potentially resulting in loss of data integrity.