VYPR

Epyc 7252 Firmware

by AMD

CVEs (73)

  • CVE-2023-20533MedNov 14, 2023
    risk 0.40cvss 6.1epss 0.01

    Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

  • CVE-2023-20523MedJan 11, 2023
    risk 0.37cvss 5.7epss 0.00

    TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.

  • CVE-2023-20593MedJul 24, 2023
    risk 0.36cvss 5.5epss 0.05

    An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

  • CVE-2021-26371MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.

  • CVE-2021-26354MedMay 9, 2023
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.

  • CVE-2022-23824MedNov 9, 2022
    risk 0.36cvss 5.5epss 0.01

    IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

  • CVE-2021-46778MedAug 10, 2022
    risk 0.36cvss 5.6epss 0.00

    Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may…

  • CVE-2021-26388MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.

  • CVE-2021-26378MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

  • CVE-2021-26376MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.

  • CVE-2021-26375MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.

  • CVE-2021-26373MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.

  • CVE-2021-26372MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.

  • CVE-2021-26364MedMay 11, 2022
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.

  • CVE-2021-26401MedMar 11, 2022
    risk 0.36cvss 5.6epss 0.00

    LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

  • CVE-2020-12966MedFeb 4, 2022
    risk 0.36cvss 5.5epss 0.00

    AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this…

  • CVE-2021-26337MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA read from invalid DRAM address to SRAM resulting in SMU not servicing further requests.

  • CVE-2021-26336MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subsequent failure to service any further requests from other components.

  • CVE-2021-26330MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.

  • CVE-2021-26321MedNov 16, 2021
    risk 0.36cvss 5.5epss 0.00

    Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.