VYPR

PMFW

by AMD

CVEs (3)

  • CVE-2023-20509MedAug 13, 2024
    risk 0.34cvss 5.2epss 0.00

    An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity.

  • CVE-2023-20510MedAug 13, 2024
    risk 0.31cvss 4.7epss 0.00

    An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.

  • CVE-2023-20512LowAug 13, 2024
    risk 0.12cvss 1.9epss 0.00

    A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.