VYPR

EPYC Processors

by AMD

CVEs (28)

  • CVE-2023-20594MedSep 20, 2023
    risk 0.29cvss 4.4epss 0.00

    Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

  • CVE-2023-20573LowJan 11, 2024
    risk 0.21cvss 3.2epss 0.00

    A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.

  • CVE-2023-20521LowNov 14, 2023
    risk 0.21cvss 3.3epss 0.00

    TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.

  • CVE-2023-20519LowNov 14, 2023
    risk 0.21cvss 3.3epss 0.00

    A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.

  • CVE-2021-46766LowNov 14, 2023
    risk 0.16cvss 2.5epss 0.00

    Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.

  • CVE-2023-20526LowNov 14, 2023
    risk 0.12cvss 1.9epss 0.00

    Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.

  • CVE-2022-23830LowNov 14, 2023
    risk 0.12cvss 1.9epss 0.00

    SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.

  • CVE-2021-26345LowNov 14, 2023
    risk 0.12cvss 1.9epss 0.00

    Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.

Page 2 of 2