VYPR

Athlon Gold 3150g Firmware

by AMD

CVEs (4)

  • CVE-2021-46754CriMay 9, 2023
    risk 0.59cvss 9.1epss 0.01

    Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and…

  • CVE-2022-23815HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.

  • CVE-2023-20589MedAug 8, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 

  • CVE-2023-20521LowNov 14, 2023
    risk 0.21cvss 3.3epss 0.00

    TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.