VYPR

Epyc 7573x Firmware

by AMD

CVEs (71)

  • CVE-2021-26397HigMay 9, 2023
    risk 0.46cvss 7.1epss 0.00

    Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.

  • CVE-2021-26402HigJan 11, 2023
    risk 0.46cvss 7.1epss 0.00

    Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.

  • CVE-2021-26370HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.

  • CVE-2021-26332HigMay 10, 2022
    risk 0.46cvss 7.1epss 0.00

    Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.

  • CVE-2021-46774MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2021-46775MedMay 9, 2023
    risk 0.44cvss 6.8epss 0.00

    Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.

  • CVE-2023-20591MedAug 13, 2024
    risk 0.42cvss 6.5epss 0.00

    Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.

  • CVE-2023-20592MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

  • CVE-2023-20575MedJul 11, 2023
    risk 0.42cvss 6.5epss 0.01

    A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.

  • CVE-2023-20527MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.

  • CVE-2023-20525MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.

  • CVE-2023-20533MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2024-21978MedAug 5, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.

  • CVE-2023-31355MedAug 5, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.

  • CVE-2023-31346MedFeb 13, 2024
    risk 0.39cvss 6.0epss 0.00

    Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests.

  • CVE-2023-20523MedJan 11, 2023
    risk 0.37cvss 5.7epss 0.00

    TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.

  • CVE-2021-26371MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.

  • CVE-2021-26354MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.

  • CVE-2021-26404MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

  • CVE-2021-26355MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.