Ryzen 5 5625u Firmware
by AMD
CVEs (47)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-20569 | Med | 0.31 | 4.7 | 0.07 | Aug 8, 2023 | A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. | ||
| CVE-2022-27672 | Med | 0.31 | 4.7 | 0.00 | Mar 1, 2023 | When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure. | ||
| CVE-2023-20594 | Med | 0.29 | 4.4 | 0.00 | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. | ||
| CVE-2021-26382 | Med | 0.29 | 4.4 | 0.00 | Jul 14, 2022 | An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for authenticating an ACP firmware image, potentially resulting in a denial of service. | ||
| CVE-2021-26368 | Med | 0.29 | 4.4 | 0.00 | May 12, 2022 | Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service. | ||
| CVE-2021-26363 | Med | 0.29 | 4.4 | 0.00 | May 12, 2022 | A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure. | ||
| CVE-2023-20521 | Low | 0.21 | 3.3 | 0.00 | Nov 14, 2023 | TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. |
- risk 0.31cvss 4.7epss 0.07
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
- risk 0.31cvss 4.7epss 0.00
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
- risk 0.29cvss 4.4epss 0.00
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
- risk 0.29cvss 4.4epss 0.00
An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for authenticating an ACP firmware image, potentially resulting in a denial of service.
- risk 0.29cvss 4.4epss 0.00
Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unmap memory owned by a higher privileged process resulting in a denial of service.
- risk 0.29cvss 4.4epss 0.00
A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
- risk 0.21cvss 3.3epss 0.00
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
Page 3 of 3