VYPR

Ryzen 5 2700x Firmware

by AMD

CVEs (6)

  • CVE-2023-20559HigApr 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.

  • CVE-2021-26316HigJan 11, 2023
    risk 0.51cvss 7.8epss 0.00

    Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.

  • CVE-2021-26384HigJul 14, 2022
    risk 0.51cvss 7.8epss 0.00

    A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potential loss of resources.

  • CVE-2022-23823MedJun 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

  • CVE-2021-26390MedMay 10, 2022
    risk 0.40cvss 6.2epss 0.00

    A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data.

  • CVE-2022-23824MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.01

    IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.