Epyc 7773x Firmware
by AMD
CVEs (35)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23824 | Med | 0.36 | 5.5 | 0.01 | Nov 9, 2022 | IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. | ||
| CVE-2021-26372 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service. | ||
| CVE-2021-26348 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity. | ||
| CVE-2021-26339 | Med | 0.36 | 5.5 | 0.00 | May 11, 2022 | A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated… | ||
| CVE-2023-20584 | Med | 0.34 | 5.3 | 0.00 | Aug 13, 2024 | IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity. | ||
| CVE-2023-20566 | Med | 0.34 | 5.3 | 0.00 | Nov 14, 2023 | Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity. | ||
| CVE-2023-31347 | Med | 0.32 | 4.9 | 0.00 | Feb 13, 2024 | Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity. | ||
| CVE-2023-20569 | Med | 0.31 | 4.7 | 0.07 | Aug 8, 2023 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | ||
| CVE-2021-26347 | Med | 0.31 | 4.7 | 0.00 | May 11, 2022 | Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service. | ||
| CVE-2021-46762 | Low | 0.25 | 3.9 | 0.00 | May 9, 2023 | Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service. | ||
| CVE-2023-20573 | Low | 0.21 | 3.2 | 0.00 | Jan 11, 2024 | A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information. | ||
| CVE-2023-20521 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2023 | TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. | ||
| CVE-2023-20528 | Low | 0.16 | 2.4 | 0.00 | Jan 11, 2023 | Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality. | ||
| CVE-2022-23830 | Low | 0.12 | 1.9 | 0.00 | Nov 14, 2023 | SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity. | ||
| CVE-2021-26345 | Low | 0.12 | 1.9 | 0.00 | Nov 14, 2023 | Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service. |
- risk 0.36cvss 5.5epss 0.01
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
- risk 0.36cvss 5.5epss 0.00
Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
- risk 0.36cvss 5.5epss 0.00
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
- risk 0.36cvss 5.5epss 0.00
A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated…
- risk 0.34cvss 5.3epss 0.00
IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to bypass RMP checks in SEV-SNP, potentially leading to a loss of guest integrity.
- risk 0.34cvss 5.3epss 0.00
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
- risk 0.32cvss 4.9epss 0.00
Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
- risk 0.31cvss 4.7epss 0.07
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
- risk 0.31cvss 4.7epss 0.00
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
- risk 0.25cvss 3.9epss 0.00
Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
- risk 0.21cvss 3.2epss 0.00
A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.
- risk 0.21cvss 3.3epss 0.00
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
- risk 0.16cvss 2.4epss 0.00
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
- risk 0.12cvss 1.9epss 0.00
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
- risk 0.12cvss 1.9epss 0.00
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
Page 2 of 2