VYPR

Ryzen 3 3250u Firmware

by AMD

CVEs (36)

  • CVE-2022-23821CriNov 14, 2023
    risk 0.64cvss 9.8epss 0.01

    Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.

  • CVE-2023-20559HigApr 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.

  • CVE-2023-20558HigApr 2, 2023
    risk 0.57cvss 8.8epss 0.01

    Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.

  • CVE-2021-26365HigMay 9, 2023
    risk 0.53cvss 8.2epss 0.01

    Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.

  • CVE-2021-26392HigNov 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.

  • CVE-2020-12931HigNov 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.

  • CVE-2020-12930HigNov 9, 2022
    risk 0.51cvss 7.8epss 0.00

    Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.

  • CVE-2021-26384HigJul 14, 2022
    risk 0.51cvss 7.8epss 0.00

    A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potential loss of resources.

  • CVE-2022-23815HigAug 13, 2024
    risk 0.49cvss 7.5epss 0.00

    Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.

  • CVE-2022-23820HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

  • CVE-2021-26356HigMay 9, 2023
    risk 0.48cvss 7.4epss 0.00

    A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.

  • CVE-2021-46774MedNov 14, 2023
    risk 0.44cvss 6.7epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2023-20589MedAug 8, 2023
    risk 0.44cvss 6.8epss 0.01

    An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 

  • CVE-2022-29900MedJul 12, 2022
    risk 0.43cvss 6.5epss 0.04

    Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

  • CVE-2023-4969MedJan 16, 2024
    risk 0.42cvss 6.5epss 0.01

    A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.

  • CVE-2022-23825MedJul 14, 2022
    risk 0.42cvss 6.5epss 0.01

    Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

  • CVE-2022-23823MedJun 15, 2022
    risk 0.42cvss 6.5epss 0.01

    A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

  • CVE-2023-20533MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2023-20579MedFeb 13, 2024
    risk 0.39cvss 6.0epss 0.00

    Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

  • CVE-2023-20597MedSep 20, 2023
    risk 0.36cvss 5.5epss 0.00

    Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

Page 1 of 2