7.5

CVE-2020-12965

When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.

Data is provided by the National Vulnerability Database (NVD)
AmdRyzen Pro 5650g Firmware Version-
   AmdRyzen Pro 5650g Version-
AmdRyzen Pro 5650ge Firmware Version-
   AmdRyzen Pro 5650ge Version-
AmdRyzen Pro 5750g Firmware Version-
   AmdRyzen Pro 5750g Version-
AmdRyzen Pro 5750ge Firmware Version-
   AmdRyzen Pro 5750ge Version-
AmdRyzen Pro 5350g Firmware Version-
   AmdRyzen Pro 5350g Version-
AmdRyzen Pro 5350ge Firmware Version-
   AmdRyzen Pro 5350ge Version-
AmdRyzen Pro 4750g Firmware Version-
   AmdRyzen Pro 4750g Version-
AmdRyzen Pro 4750ge Firmware Version-
   AmdRyzen Pro 4750ge Version-
AmdRyzen Pro 4650g Firmware Version-
   AmdRyzen Pro 4650g Version-
AmdRyzen Pro 4650ge Firmware Version-
   AmdRyzen Pro 4650ge Version-
AmdRyzen Pro 4350g Firmware Version-
   AmdRyzen Pro 4350g Version-
AmdRyzen Pro 4350ge Firmware Version-
   AmdRyzen Pro 4350ge Version-
AmdRyzen Pro 3900 Firmware Version-
   AmdRyzen Pro 3900 Version-
AmdRyzen Pro 3700 Firmware Version-
   AmdRyzen Pro 3700 Version-
AmdRyzen Pro 3600 Firmware Version-
   AmdRyzen Pro 3600 Version-
AmdRyzen Pro 3400g Firmware Version-
   AmdRyzen Pro 3400g Version-
AmdRyzen Pro 3400ge Firmware Version-
   AmdRyzen Pro 3400ge Version-
AmdRyzen Pro 3350g Firmware Version-
   AmdRyzen Pro 3350g Version-
AmdRyzen Pro 3200g Firmware Version-
   AmdRyzen Pro 3200g Version-
AmdRyzen Pro 3200ge Firmware Version-
   AmdRyzen Pro 3200ge Version-
AmdRyzen Pro 2400g Firmware Version-
   AmdRyzen Pro 2400g Version-
AmdRyzen Pro 2400ge Firmware Version-
   AmdRyzen Pro 2400ge Version-
AmdRyzen Pro 2200g Firmware Version-
   AmdRyzen Pro 2200g Version-
AmdRyzen Pro 2200ge Firmware Version-
   AmdRyzen Pro 2200ge Version-
AmdAthlon Pro 300ge Firmware Version-
   AmdAthlon Pro 300ge Version-
AmdAthlon Pro 200ge Firmware Version-
   AmdAthlon Pro 200ge Version-
AmdRyzen 5950x Firmware Version-
   AmdRyzen 5950x Version-
AmdRyzen 5800x3d Firmware Version-
   AmdRyzen 5800x3d Version-
AmdRyzen 5900x Firmware Version-
   AmdRyzen 5900x Version-
AmdRyzen 5800x Firmware Version-
   AmdRyzen 5800x Version-
AmdRyzen 5600x Firmware Version-
   AmdRyzen 5600x Version-
AmdRyzen 5700g Firmware Version-
   AmdRyzen 5700g Version-
AmdRyzen 5600g Firmware Version-
   AmdRyzen 5600g Version-
AmdRyzen 5700g Firmware Version-
   AmdRyzen 5700g Version-
AmdRyzen 5700ge Firmware Version-
   AmdRyzen 5700ge Version-
AmdRyzen 5600g Firmware Version-
   AmdRyzen 5600g Version-
AmdRyzen 5600ge Firmware Version-
   AmdRyzen 5600ge Version-
AmdRyzen 5300g Firmware Version-
   AmdRyzen 5300g Version-
AmdRyzen 5300ge Firmware Version-
   AmdRyzen 5300ge Version-
AmdRyzen 4700g Firmware Version-
   AmdRyzen 4700g Version-
AmdRyzen 4600g Firmware Version-
   AmdRyzen 4600g Version-
AmdRyzen 4300g Firmware Version-
   AmdRyzen 4300g Version-
AmdRyzen 4700ge Firmware Version-
   AmdRyzen 4700ge Version-
AmdRyzen 4600ge Firmware Version-
   AmdRyzen 4600ge Version-
AmdRyzen 4300ge Firmware Version-
   AmdRyzen 4300ge Version-
AmdAthlon 3150ge Firmware Version-
   AmdAthlon 3150ge Version-
AmdAthlon 3150g Firmware Version-
   AmdAthlon 3150g Version-
AmdAthlon 3050ge Firmware Version-
   AmdAthlon 3050ge Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.82% 0.737
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.