Epyc 7763 Firmware
by AMD
CVEs (96)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-20532 | Med | 0.34 | 5.3 | 0.01 | Jan 11, 2023 | Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service. | ||
| CVE-2023-31347 | Med | 0.32 | 4.9 | 0.00 | Feb 13, 2024 | Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity. | ||
| CVE-2023-20569 | Med | 0.31 | 4.7 | 0.07 | Aug 8, 2023 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | ||
| CVE-2021-26350 | Med | 0.31 | 4.7 | 0.00 | May 11, 2022 | A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service. | ||
| CVE-2021-26347 | Med | 0.31 | 4.7 | 0.00 | May 11, 2022 | Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service. | ||
| CVE-2023-20594 | Med | 0.29 | 4.4 | 0.00 | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. | ||
| CVE-2021-26396 | Med | 0.29 | 4.4 | 0.00 | Jan 11, 2023 | Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest. | ||
| CVE-2021-26328 | Med | 0.29 | 4.4 | 0.00 | Jan 11, 2023 | Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests. | ||
| CVE-2021-46762 | Low | 0.25 | 3.9 | 0.00 | May 9, 2023 | Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service. | ||
| CVE-2023-20573 | Low | 0.21 | 3.2 | 0.00 | Jan 11, 2024 | A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information. | ||
| CVE-2023-20521 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2023 | TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. | ||
| CVE-2021-26342 | Low | 0.21 | 3.3 | 0.00 | May 11, 2022 | In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB… | ||
| CVE-2023-20528 | Low | 0.16 | 2.4 | 0.00 | Jan 11, 2023 | Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality. | ||
| CVE-2023-20526 | Low | 0.12 | 1.9 | 0.00 | Nov 14, 2023 | Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality. | ||
| CVE-2022-23830 | Low | 0.12 | 1.9 | 0.00 | Nov 14, 2023 | SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity. | ||
| CVE-2021-26345 | Low | 0.12 | 1.9 | 0.00 | Nov 14, 2023 | Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service. |
- risk 0.34cvss 5.3epss 0.01
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
- risk 0.32cvss 4.9epss 0.00
Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
- risk 0.31cvss 4.7epss 0.07
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
- risk 0.31cvss 4.7epss 0.00
A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.
- risk 0.31cvss 4.7epss 0.00
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
- risk 0.29cvss 4.4epss 0.00
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
- risk 0.29cvss 4.4epss 0.00
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
- risk 0.29cvss 4.4epss 0.00
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
- risk 0.25cvss 3.9epss 0.00
Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
- risk 0.21cvss 3.2epss 0.00
A privileged attacker can prevent delivery of debug exceptions to SEV-SNP guests potentially resulting in guests not receiving expected debug information.
- risk 0.21cvss 3.3epss 0.00
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
- risk 0.21cvss 3.3epss 0.00
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB…
- risk 0.16cvss 2.4epss 0.00
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
- risk 0.12cvss 1.9epss 0.00
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
- risk 0.12cvss 1.9epss 0.00
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
- risk 0.12cvss 1.9epss 0.00
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
Page 5 of 5