CVE-2023-20533
- EPSS 0.03%
- Veröffentlicht 14.11.2023 19:15:15
- Zuletzt bearbeitet 21.11.2024 07:41:06
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
CVE-2021-46774
- EPSS 0.02%
- Veröffentlicht 14.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:34:41
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
CVE-2022-23820
- EPSS 0.18%
- Veröffentlicht 14.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:49:18
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
CVE-2022-23821
- EPSS 0.34%
- Veröffentlicht 14.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:49:18
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
CVE-2023-20589
- EPSS 0.08%
- Veröffentlicht 08.08.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:41:10
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. ...
CVE-2023-20593
- EPSS 6.32%
- Veröffentlicht 24.07.2023 20:15:10
- Zuletzt bearbeitet 13.02.2025 17:16:01
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.
CVE-2021-26354
- EPSS 0.04%
- Veröffentlicht 09.05.2023 19:15:10
- Zuletzt bearbeitet 28.01.2025 16:15:27
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
CVE-2021-26356
- EPSS 0.14%
- Veröffentlicht 09.05.2023 19:15:10
- Zuletzt bearbeitet 28.01.2025 16:15:29
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.
CVE-2021-26371
- EPSS 0.06%
- Veröffentlicht 09.05.2023 19:15:10
- Zuletzt bearbeitet 28.01.2025 16:15:29
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.
CVE-2023-20558
- EPSS 0.26%
- Veröffentlicht 02.04.2023 21:15:08
- Zuletzt bearbeitet 20.02.2025 20:15:44
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.