Epyc 7001 Firmware
by AMD
CVEs (26)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2020-12966 | Med | 0.36 | 5.5 | 0.00 | Feb 4, 2022 | AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this… | ||
| CVE-2021-26330 | Med | 0.36 | 5.5 | 0.00 | Nov 16, 2021 | AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources. | ||
| CVE-2020-12954 | Med | 0.36 | 5.5 | 0.00 | Nov 16, 2021 | A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification. | ||
| CVE-2023-20521 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2023 | TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. | ||
| CVE-2021-26342 | Low | 0.21 | 3.3 | 0.00 | May 11, 2022 | In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB… | ||
| CVE-2023-20526 | Low | 0.12 | 1.9 | 0.00 | Nov 14, 2023 | Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality. |
- risk 0.36cvss 5.5epss 0.00
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this…
- risk 0.36cvss 5.5epss 0.00
AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.
- risk 0.36cvss 5.5epss 0.00
A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.
- risk 0.21cvss 3.3epss 0.00
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
- risk 0.21cvss 3.3epss 0.00
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB…
- risk 0.12cvss 1.9epss 0.00
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
Page 2 of 2