CVE-2023-20592
- EPSS 0.36%
- Veröffentlicht 14.11.2023 19:15:16
- Zuletzt bearbeitet 21.11.2024 07:41:11
Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity....
CVE-2023-20526
- EPSS 0.04%
- Veröffentlicht 14.11.2023 19:15:15
- Zuletzt bearbeitet 21.11.2024 07:41:05
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
CVE-2023-20521
- EPSS 0.04%
- Veröffentlicht 14.11.2023 19:15:15
- Zuletzt bearbeitet 21.11.2024 07:41:04
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
CVE-2023-20533
- EPSS 0.03%
- Veröffentlicht 14.11.2023 19:15:15
- Zuletzt bearbeitet 21.11.2024 07:41:06
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
CVE-2023-20566
- EPSS 0.05%
- Veröffentlicht 14.11.2023 19:15:15
- Zuletzt bearbeitet 21.11.2024 07:41:08
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
CVE-2022-23830
- EPSS 0.07%
- Veröffentlicht 14.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:49:20
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
CVE-2021-46774
- EPSS 0.02%
- Veröffentlicht 14.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 06:34:41
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
CVE-2021-26345
- EPSS 0.03%
- Veröffentlicht 14.11.2023 19:15:10
- Zuletzt bearbeitet 21.11.2024 05:56:09
Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.
CVE-2023-20569
- EPSS 0.65%
- Veröffentlicht 08.08.2023 18:15:11
- Zuletzt bearbeitet 21.11.2024 07:41:08
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure. ...
CVE-2023-20575
- EPSS 0.33%
- Veröffentlicht 11.07.2023 19:15:09
- Zuletzt bearbeitet 27.11.2024 16:15:08
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive infor...