Ryzen 6600u Firmware
by AMD
CVEs (5)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-46753 | Cri | 0.59 | 9.1 | 0.01 | May 9, 2023 | Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and… | ||
| CVE-2021-46773 | Hig | 0.57 | 8.8 | 0.01 | May 9, 2023 | Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution. | ||
| CVE-2021-46765 | Hig | 0.49 | 7.5 | 0.01 | May 9, 2023 | Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service. | ||
| CVE-2023-20597 | Med | 0.36 | 5.5 | 0.00 | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. | ||
| CVE-2023-20594 | Med | 0.29 | 4.4 | 0.00 | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
- risk 0.59cvss 9.1epss 0.01
Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and…
- risk 0.57cvss 8.8epss 0.01
Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution.
- risk 0.49cvss 7.5epss 0.01
Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service.
- risk 0.36cvss 5.5epss 0.00
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
- risk 0.29cvss 4.4epss 0.00
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.