Epyc 7473x Firmware
by AMD
CVEs (55)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-20591 | Med | 0.42 | 6.5 | 0.00 | Aug 13, 2024 | Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability. | ||
| CVE-2023-20592 | Med | 0.42 | 6.5 | 0.01 | Nov 14, 2023 | Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity. | ||
| CVE-2023-20575 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information. | ||
| CVE-2023-20533 | Med | 0.40 | 6.1 | 0.01 | Nov 14, 2023 | Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service. | ||
| CVE-2024-21978 | Med | 0.39 | 6.0 | 0.00 | Aug 5, 2024 | Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption. | ||
| CVE-2023-31355 | Med | 0.39 | 6.0 | 0.00 | Aug 5, 2024 | Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest. | ||
| CVE-2023-31346 | Med | 0.39 | 6.0 | 0.00 | Feb 13, 2024 | Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests. | ||
| CVE-2021-26371 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure. | ||
| CVE-2021-26354 | Med | 0.36 | 5.5 | 0.00 | May 9, 2023 | Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity. | ||
| CVE-2021-26404 | Med | 0.36 | 5.5 | 0.00 | Jan 11, 2023 | Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. | ||
| CVE-2022-23824 | Med | 0.36 | 5.5 | 0.01 | Nov 9, 2022 | IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. | ||
| CVE-2021-46778 | Med | 0.36 | 5.6 | 0.00 | Aug 10, 2022 | Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may… | ||
| CVE-2021-26388 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service. | ||
| CVE-2021-26378 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service. | ||
| CVE-2021-26376 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service. | ||
| CVE-2021-26375 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service. | ||
| CVE-2021-26373 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service. | ||
| CVE-2021-26372 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service. | ||
| CVE-2021-26364 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service. | ||
| CVE-2021-26349 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into trusting a dishonest Migration Agent (MA). |
- risk 0.42cvss 6.5epss 0.00
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.
- risk 0.42cvss 6.5epss 0.01
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
- risk 0.42cvss 6.5epss 0.01
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
- risk 0.40cvss 6.1epss 0.01
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
- risk 0.39cvss 6.0epss 0.00
Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.
- risk 0.39cvss 6.0epss 0.00
Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.
- risk 0.39cvss 6.0epss 0.00
Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.
- risk 0.36cvss 5.5epss 0.00
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
- risk 0.36cvss 5.5epss 0.00
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
- risk 0.36cvss 5.5epss 0.00
Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.
- risk 0.36cvss 5.5epss 0.01
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
- risk 0.36cvss 5.6epss 0.00
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may…
- risk 0.36cvss 5.5epss 0.00
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.
- risk 0.36cvss 5.5epss 0.00
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
- risk 0.36cvss 5.5epss 0.00
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.
- risk 0.36cvss 5.5epss 0.00
Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.
- risk 0.36cvss 5.5epss 0.00
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.
- risk 0.36cvss 5.5epss 0.00
Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
- risk 0.36cvss 5.5epss 0.00
Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.
- risk 0.36cvss 5.5epss 0.00
Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into trusting a dishonest Migration Agent (MA).
Page 2 of 3