VYPR

Epyc 7261 Firmware

by AMD

CVEs (29)

  • CVE-2023-20520CriMay 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.

  • CVE-2021-46756CriMay 9, 2023
    risk 0.59cvss 9.1epss 0.01

    Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity. …

  • CVE-2021-26340HigDec 10, 2021
    risk 0.55cvss 8.4epss 0.00

    A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).

  • CVE-2021-26398HigJan 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.

  • CVE-2020-12944HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.

  • CVE-2023-20578HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.00

    A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.

  • CVE-2021-26406HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service.

  • CVE-2021-26322HigNov 16, 2021
    risk 0.49cvss 7.5epss 0.01

    Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”.

  • CVE-2020-12988HigJun 11, 2021
    risk 0.49cvss 7.5epss 0.01

    A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.

  • CVE-2021-26356HigMay 9, 2023
    risk 0.48cvss 7.4epss 0.00

    A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.

  • CVE-2021-46774MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2022-29900MedJul 12, 2022
    risk 0.43cvss 6.5epss 0.04

    Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

  • CVE-2023-20592MedNov 14, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

  • CVE-2023-20527MedJan 11, 2023
    risk 0.42cvss 6.5epss 0.01

    Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.

  • CVE-2022-23825MedJul 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

  • CVE-2022-23823MedJun 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

  • CVE-2021-46744MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.00

    An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.

  • CVE-2021-26341MedMar 11, 2022
    risk 0.42cvss 6.5epss 0.00

    Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.

  • CVE-2023-20588MedAug 8, 2023
    risk 0.37cvss 5.5epss 0.12

    A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 

  • CVE-2021-26371MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.

Page 1 of 2