VYPR

Epyc 7313 Firmware

by AMD

CVEs (88)

  • CVE-2023-20592MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

  • CVE-2023-20575MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.

  • CVE-2023-20527MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.

  • CVE-2023-20525MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.

  • CVE-2021-46744MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.

  • CVE-2023-20533MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2024-21978MedAug 5, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

  • CVE-2023-31355MedAug 5, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.

  • CVE-2023-31346MedFeb 13, 2024
    risk 0.39cvss 6.0epss 0.00

    Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

  • CVE-2023-20523MedJan 11, 2023
    risk 0.37cvss 5.7epss 0.00

    TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.

  • CVE-2021-26371MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.

  • CVE-2021-26354MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.

  • CVE-2021-26404MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

  • CVE-2021-26355MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.

  • CVE-2021-26343MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.

  • CVE-2022-23824MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.01

    IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

  • CVE-2021-46778MedAug 10, 2022
    risk 0.36cvss 5.6epss 0.00

    Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may…

  • CVE-2021-26349MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into trusting a dishonest Migration Agent (MA).

  • CVE-2021-26348MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.

  • CVE-2021-26339MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated…