CVE-2023-20524
- EPSS 0.15%
- Published 09.05.2023 19:15:11
- Last modified 28.01.2025 16:15:35
An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.
CVE-2023-20520
- EPSS 0.31%
- Published 09.05.2023 19:15:11
- Last modified 28.01.2025 16:15:34
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.
CVE-2021-46775
- EPSS 0.06%
- Published 09.05.2023 19:15:11
- Last modified 28.01.2025 16:15:32
Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.
CVE-2021-46769
- EPSS 0.16%
- Published 09.05.2023 19:15:11
- Last modified 28.01.2025 16:15:32
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.
CVE-2021-46764
- EPSS 0.12%
- Published 09.05.2023 19:15:11
- Last modified 28.01.2025 16:15:32
Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.
CVE-2021-46763
- EPSS 0.09%
- Published 09.05.2023 19:15:11
- Last modified 28.01.2025 16:15:32
Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.
CVE-2021-46762
- EPSS 0.03%
- Published 09.05.2023 19:15:11
- Last modified 21.11.2024 06:34:39
Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
CVE-2021-26406
- EPSS 0.15%
- Published 09.05.2023 19:15:10
- Last modified 28.01.2025 16:15:30
Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service.
CVE-2021-26354
- EPSS 0.04%
- Published 09.05.2023 19:15:10
- Last modified 28.01.2025 16:15:27
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
CVE-2021-26356
- EPSS 0.14%
- Published 09.05.2023 19:15:10
- Last modified 28.01.2025 16:15:29
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.