VYPR

Ryzen 5 3400g Firmware

by AMD

CVEs (26)

  • CVE-2021-26339MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated…

  • CVE-2021-26401MedMar 11, 2022
    risk 0.36cvss 5.6epss 0.00

    LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

  • CVE-2021-26337MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.

  • CVE-2021-26336MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components.

  • CVE-2021-26368MedMay 12, 2022
    risk 0.29cvss 4.4epss 0.00

    Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.

  • CVE-2021-26363MedMay 12, 2022
    risk 0.29cvss 4.4epss 0.00

    A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.

Page 2 of 2