VYPR

Ryzen 7 5700 Firmware

by AMD

CVEs (7)

  • CVE-2022-23821CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.

  • CVE-2023-20571HigNov 14, 2023
    risk 0.53cvss 8.1epss 0.00

    A race condition in System Management Mode (SMM) code may allow an attacker using a compromised user space to leverage CVE-2018-8897 potentially resulting in privilege escalation.

  • CVE-2023-20565HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

  • CVE-2023-20563HigNov 14, 2023
    risk 0.51cvss 7.8epss 0.00

    Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

  • CVE-2022-23820HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

  • CVE-2023-20589MedAug 8, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 

  • CVE-2023-20569MedAug 8, 2023
    risk 0.31cvss 4.7epss 0.07

    A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.