VYPR

power management firmware (PMFW)

by AMD

CVEs (6)

  • CVE-2023-31313HigFeb 12, 2026
    risk 0.47cvss 7.2epss 0.00

    An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.

  • CVE-2024-36346MedSep 6, 2025
    risk 0.39cvss 6.0epss 0.00

    Improper input validation in AMD Power Management Firmware (PMFW) could allow a privileged attacker from Guest VM to send arbitrary input data potentially causing a GPU Reset condition.

  • CVE-2023-31310MedAug 13, 2024
    risk 0.33cvss 5.0epss 0.00

    Improper input validation in Power Management Firmware (PMFW) may allow an attacker with privileges to send a malformed input for the "set temperature input selection" command, potentially resulting in a loss of integrity and/or availability.

  • CVE-2023-20513LowAug 13, 2024
    risk 0.21cvss 3.3epss 0.00

    An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a denial of service.

  • CVE-2023-31307LowAug 13, 2024
    risk 0.15cvss 2.3epss 0.00

    Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.

  • CVE-2023-31305LowAug 13, 2024
    risk 0.12cvss 1.9epss 0.00

    Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure.