VYPR

Ryzen 5 3400g Firmware

by AMD

CVEs (12)

  • CVE-2021-26386HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution.

  • CVE-2021-26369HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.00

    A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

  • CVE-2021-26366HigMay 12, 2022
    risk 0.46cvss 7.1epss 0.00

    An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.

  • CVE-2023-20589MedAug 8, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 

  • CVE-2023-4969MedJan 16, 2024
    risk 0.42cvss 6.5epss 0.01

    A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

  • CVE-2022-23823MedJun 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

  • CVE-2021-26346MedJan 11, 2023
    risk 0.36cvss 5.5epss 0.00

    Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

  • CVE-2022-23824MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.01

    IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

  • CVE-2021-26339MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated…

  • CVE-2021-26401MedMar 11, 2022
    risk 0.36cvss 5.6epss 0.00

    LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

  • CVE-2021-26337MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.

  • CVE-2021-26336MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components.