CVE-2023-20594
- EPSS 0.05%
- Veröffentlicht 20.09.2023 18:15:12
- Zuletzt bearbeitet 27.06.2025 22:15:23
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
CVE-2023-20531
- EPSS 0.23%
- Veröffentlicht 11.01.2023 08:15:14
- Zuletzt bearbeitet 07.04.2025 19:15:48
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
CVE-2023-20532
- EPSS 0.09%
- Veröffentlicht 11.01.2023 08:15:14
- Zuletzt bearbeitet 07.04.2025 19:15:48
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
CVE-2023-20523
- EPSS 0.07%
- Veröffentlicht 11.01.2023 08:15:13
- Zuletzt bearbeitet 07.04.2025 16:15:20
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.
CVE-2023-20525
- EPSS 0.14%
- Veröffentlicht 11.01.2023 08:15:13
- Zuletzt bearbeitet 07.04.2025 16:15:20
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
CVE-2023-20527
- EPSS 0.14%
- Veröffentlicht 11.01.2023 08:15:13
- Zuletzt bearbeitet 07.04.2025 16:15:20
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
CVE-2023-20528
- EPSS 0.08%
- Veröffentlicht 11.01.2023 08:15:13
- Zuletzt bearbeitet 07.04.2025 19:15:47
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
CVE-2023-20529
- EPSS 0.23%
- Veröffentlicht 11.01.2023 08:15:13
- Zuletzt bearbeitet 07.04.2025 19:15:48
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
CVE-2023-20530
- EPSS 0.17%
- Veröffentlicht 11.01.2023 08:15:13
- Zuletzt bearbeitet 07.04.2025 19:15:48
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
CVE-2021-26355
- EPSS 0.06%
- Veröffentlicht 11.01.2023 08:15:11
- Zuletzt bearbeitet 09.04.2025 15:15:43
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.