Ryzen 5 3600 Firmware
by AMD
CVEs (36)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-23821 | Cri | 0.64 | 9.8 | 0.01 | Nov 14, 2023 | Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution. | ||
| CVE-2023-20559 | Hig | 0.57 | 8.8 | 0.01 | Apr 2, 2023 | Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges. | ||
| CVE-2023-20558 | Hig | 0.57 | 8.8 | 0.01 | Apr 2, 2023 | Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges. | ||
| CVE-2023-20555 | Hig | 0.51 | 7.8 | 0.00 | Aug 8, 2023 | Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM. | ||
| CVE-2021-26392 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA. | ||
| CVE-2020-12931 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. | ||
| CVE-2020-12930 | Hig | 0.51 | 7.8 | 0.00 | Nov 9, 2022 | Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. | ||
| CVE-2021-26386 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution. | ||
| CVE-2021-26317 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution. | ||
| CVE-2021-26369 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2022 | A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses. | ||
| CVE-2022-23820 | Hig | 0.49 | 7.5 | 0.01 | Nov 14, 2023 | Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution. | ||
| CVE-2021-26356 | Hig | 0.48 | 7.4 | 0.00 | May 9, 2023 | A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure. | ||
| CVE-2021-26366 | Hig | 0.46 | 7.1 | 0.00 | May 12, 2022 | An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity. | ||
| CVE-2021-46774 | Med | 0.44 | 6.7 | 0.01 | Nov 14, 2023 | Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service. | ||
| CVE-2023-20589 | Med | 0.44 | 6.8 | 0.01 | Aug 8, 2023 | An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. | ||
| CVE-2022-29900 | Med | 0.43 | 6.5 | 0.04 | Jul 12, 2022 | Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. | ||
| CVE-2022-23825 | Med | 0.42 | 6.5 | 0.01 | Jul 14, 2022 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. | ||
| CVE-2022-23823 | Med | 0.42 | 6.5 | 0.01 | Jun 15, 2022 | A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure. | ||
| CVE-2021-26341 | Med | 0.42 | 6.5 | 0.00 | Mar 11, 2022 | Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage. | ||
| CVE-2023-20533 | Med | 0.40 | 6.1 | 0.01 | Nov 14, 2023 | Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service. |
- risk 0.64cvss 9.8epss 0.01
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
- risk 0.57cvss 8.8epss 0.01
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
- risk 0.57cvss 8.8epss 0.01
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
- risk 0.51cvss 7.8epss 0.00
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
- risk 0.51cvss 7.8epss 0.00
Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.
- risk 0.51cvss 7.8epss 0.00
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
- risk 0.51cvss 7.8epss 0.00
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
- risk 0.51cvss 7.8epss 0.00
A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution.
- risk 0.51cvss 7.8epss 0.00
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
- risk 0.51cvss 7.8epss 0.00
A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.
- risk 0.49cvss 7.5epss 0.01
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
- risk 0.48cvss 7.4epss 0.00
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
- risk 0.46cvss 7.1epss 0.00
An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.
- risk 0.44cvss 6.7epss 0.01
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
- risk 0.44cvss 6.8epss 0.01
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution.
- risk 0.43cvss 6.5epss 0.04
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
- risk 0.42cvss 6.5epss 0.01
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.
- risk 0.42cvss 6.5epss 0.01
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.
- risk 0.42cvss 6.5epss 0.00
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
- risk 0.40cvss 6.1epss 0.01
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
Page 1 of 2