8.2
CVE-2022-23815
- EPSS 0.06%
- Veröffentlicht 13.08.2024 17:15:18
- Zuletzt bearbeitet 18.03.2025 21:15:23
- Quelle psirt@amd.com
- Teams Watchlist Login
- Unerledigt Login
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amd ≫ Athlon Silver 3050u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Athlon Gold 3150u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 7 3780u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 7 3750h Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 7 Pro 3700u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 7 3700u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 5 3580u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 5 3550h Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 5 3500u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 3 3300u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 3 3250u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Ryzen 3 3200u Firmware Version < picassopi-fp5_1.0.0.e
Amd ≫ Athlon Gold Pro 3150g Firmware Version-
Amd ≫ Athlon Gold 3150g Firmware Version-
Amd ≫ Athlon Gold Pro 3150ge Firmware Version-
Amd ≫ Athlon Pro 300ge Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.06% | 0.194 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.2 | 1.5 | 6 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
psirt@amd.com | 7.5 | 0.8 | 6 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.