CVE-2021-26369
- EPSS 0.14%
- Published 12.05.2022 18:16:53
- Last modified 21.11.2024 05:56:13
A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.
CVE-2021-26366
- EPSS 0.13%
- Published 12.05.2022 18:16:53
- Last modified 21.11.2024 05:56:13
An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.
CVE-2021-26362
- EPSS 0.13%
- Published 12.05.2022 18:16:53
- Last modified 21.11.2024 05:56:12
A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive System Management Network (SMN) registers leading to a loss of integrity and availability.
CVE-2021-26361
- EPSS 0.13%
- Published 12.05.2022 18:16:53
- Last modified 21.11.2024 05:56:12
A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure.
CVE-2021-26388
- EPSS 0.12%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:16
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.
CVE-2021-26378
- EPSS 0.12%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:15
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
CVE-2021-26376
- EPSS 0.12%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:15
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.
CVE-2021-26375
- EPSS 0.08%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:14
Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.
CVE-2021-26373
- EPSS 0.12%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:14
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.
CVE-2021-26339
- EPSS 0.09%
- Published 11.05.2022 17:15:08
- Last modified 21.11.2024 05:56:08
A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence t...