VYPR

Epyc 7473x Firmware

by AMD

CVEs (55)

  • CVE-2023-20591MedAug 13, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.

  • CVE-2023-20592MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

  • CVE-2023-20575MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.

  • CVE-2023-20533MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2024-21978MedAug 5, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

  • CVE-2023-31355MedAug 5, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.

  • CVE-2023-31346MedFeb 13, 2024
    risk 0.39cvss 6.0epss 0.00

    Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

  • CVE-2021-26371MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.

  • CVE-2021-26354MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.

  • CVE-2021-26404MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

  • CVE-2022-23824MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.01

    IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

  • CVE-2021-46778MedAug 10, 2022
    risk 0.36cvss 5.6epss 0.00

    Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may…

  • CVE-2021-26388MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.

  • CVE-2021-26378MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

  • CVE-2021-26376MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.

  • CVE-2021-26375MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.

  • CVE-2021-26373MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.

  • CVE-2021-26372MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

  • CVE-2021-26364MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.

  • CVE-2021-26349MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into trusting a dishonest Migration Agent (MA).