Epyc 7351 Firmware
by AMD
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46756 | Cri | 0.59 | 9.1 | 0.01 | May 9, 2023 | Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity. … | ||
| CVE-2021-26340 | Hig | 0.55 | 8.4 | 0.00 | Dec 10, 2021 | A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM). | ||
| CVE-2021-26335 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution. | ||
| CVE-2021-26331 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution. | ||
| CVE-2020-12944 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution. | ||
| CVE-2023-20578 | Hig | 0.49 | 7.5 | 0.00 | Aug 13, 2024 | A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution. | ||
| CVE-2021-26406 | Hig | 0.49 | 7.5 | 0.00 | May 9, 2023 | Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service. | ||
| CVE-2021-26322 | Hig | 0.49 | 7.5 | 0.01 | Nov 16, 2021 | Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”. | ||
| CVE-2020-12988 | Hig | 0.49 | 7.5 | 0.01 | Jun 11, 2021 | A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted. | ||
| CVE-2021-26356 | Hig | 0.48 | 7.4 | 0.00 | May 9, 2023 | A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure. | ||
| CVE-2021-26408 | Hig | 0.46 | 7.1 | 0.00 | May 10, 2022 | Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality. | ||
| CVE-2020-12951 | Hig | 0.46 | 7.0 | 0.00 | Nov 16, 2021 | Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations. | ||
| CVE-2021-46774 | Med | 0.44 | 6.7 | 0.01 | Nov 14, 2023 | Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service. | ||
| CVE-2023-20592 | Med | 0.42 | 6.5 | 0.01 | Nov 14, 2023 | Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity. | ||
| CVE-2023-20575 | Med | 0.42 | 6.5 | 0.01 | Jul 11, 2023 | A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information. | ||
| CVE-2022-23823 | Med | 0.42 | 6.5 | 0.01 | Jun 15, 2022 | A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure. | ||
| CVE-2021-46744 | Med | 0.42 | 6.5 | 0.00 | May 11, 2022 | An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time. | ||
| CVE-2022-23824 | Med | 0.36 | 5.5 | 0.01 | Nov 9, 2022 | IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. | ||
| CVE-2021-26401 | Med | 0.36 | 5.6 | 0.00 | Mar 11, 2022 | LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs. | ||
| CVE-2021-26330 | Med | 0.36 | 5.5 | 0.00 | Nov 16, 2021 | AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources. |
- risk 0.59cvss 9.1epss 0.01
Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity. …
- risk 0.55cvss 8.4epss 0.00
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
- risk 0.51cvss 7.8epss 0.00
Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.00
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
- risk 0.49cvss 7.5epss 0.00
Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service.
- risk 0.49cvss 7.5epss 0.01
Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.
- risk 0.49cvss 7.5epss 0.01
A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.
- risk 0.48cvss 7.4epss 0.00
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
- risk 0.46cvss 7.1epss 0.00
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
- risk 0.46cvss 7.0epss 0.00
Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations.
- risk 0.44cvss 6.7epss 0.01
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
- risk 0.42cvss 6.5epss 0.01
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.
- risk 0.42cvss 6.5epss 0.01
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
- risk 0.42cvss 6.5epss 0.01
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
- risk 0.42cvss 6.5epss 0.00
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
- risk 0.36cvss 5.5epss 0.01
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.
- risk 0.36cvss 5.6epss 0.00
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
- risk 0.36cvss 5.5epss 0.00
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
Page 1 of 2