9

CVE-2020-12967

AMD Secure Encrypted Virtualization

The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amd ≫ Epyc 7232p Version -
Amd ≫ Epyc 7251 Version -
Amd ≫ Epyc 7252 Version -
Amd ≫ Epyc 7261 Version -
Amd ≫ Epyc 7262 Version -
Amd ≫ Epyc 7272 Version -
Amd ≫ Epyc 7281 Version -
Amd ≫ Epyc 7282 Version -
Amd ≫ Epyc 72f3 Version -
Amd ≫ Epyc 7301 Version -
Amd ≫ Epyc 7302 Version -
Amd ≫ Epyc 7302p Version -
Amd ≫ Epyc 7313 Version -
Amd ≫ Epyc 7313p Version -
Amd ≫ Epyc 7343 Version -
Amd ≫ Epyc 7351 Version -
Amd ≫ Epyc 7351p Version -
Amd ≫ Epyc 7352 Version -
Amd ≫ Epyc 7371 Version -
Amd ≫ Epyc 73f3 Version -
Amd ≫ Epyc 7401 Version -
Amd ≫ Epyc 7401p Version -
Amd ≫ Epyc 7402 Version -
Amd ≫ Epyc 7402p Version -
Amd ≫ Epyc 7413 Version -
Amd ≫ Epyc 7443 Version -
Amd ≫ Epyc 7443p Version -
Amd ≫ Epyc 7451 Version -
Amd ≫ Epyc 7452 Version -
Amd ≫ Epyc 7453 Version -
Amd ≫ Epyc 74f3 Version -
Amd ≫ Epyc 7501 Version -
Amd ≫ Epyc 7502 Version -
Amd ≫ Epyc 7502p Version -
Amd ≫ Epyc 7513 Version -
Amd ≫ Epyc 7532 Version -
Amd ≫ Epyc 7542 Version -
Amd ≫ Epyc 7543 Version -
Amd ≫ Epyc 7543p Version -
Amd ≫ Epyc 7551 Version -
Amd ≫ Epyc 7551p Version -
Amd ≫ Epyc 7552 Version -
Amd ≫ Epyc 75f3 Version -
Amd ≫ Epyc 7601 Version -
Amd ≫ Epyc 7642 Version -
Amd ≫ Epyc 7643 Version -
Amd ≫ Epyc 7662 Version -
Amd ≫ Epyc 7663 Version -
Amd ≫ Epyc 7702 Version -
Amd ≫ Epyc 7702p Version -
Amd ≫ Epyc 7713 Version -
Amd ≫ Epyc 7713p Version -
Amd ≫ Epyc 7742 Version -
Amd ≫ Epyc 7763 Version -
Amd ≫ Epyc 7f32 Version -
Amd ≫ Epyc 7f52 Version -
Amd ≫ Epyc 7f72 Version -
Amd ≫ Epyc 7h12 Version -
Amd ≫ Epyc Embedded 3101 Version -
Amd ≫ Epyc Embedded 3151 Version -
Amd ≫ Epyc Embedded 3201 Version -
Amd ≫ Epyc Embedded 3251 Version -
Amd ≫ Epyc Embedded 3255 Version -
Amd ≫ Epyc Embedded 3351 Version -
Amd ≫ Epyc Embedded 3451 Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.68% 0.74
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 9 8 10
AV:N/AC:L/Au:S/C:C/I:C/A:C
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1004
Vendor Advisory