Amd

Epyc 7473x Firmware

55 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.17%
  • Veröffentlicht 09.05.2023 19:15:10
  • Zuletzt bearbeitet 28.01.2025 16:15:29

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

  • EPSS 0.06%
  • Veröffentlicht 09.05.2023 19:15:10
  • Zuletzt bearbeitet 28.01.2025 16:15:29

A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure.

  • EPSS 0.14%
  • Veröffentlicht 09.05.2023 19:15:10
  • Zuletzt bearbeitet 28.01.2025 16:15:29

A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.

  • EPSS 0.04%
  • Veröffentlicht 09.05.2023 19:15:10
  • Zuletzt bearbeitet 28.01.2025 16:15:27

Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.

  • EPSS 0.06%
  • Veröffentlicht 11.01.2023 08:15:11
  • Zuletzt bearbeitet 08.04.2025 21:15:43

Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure.

  • EPSS 0.03%
  • Veröffentlicht 09.11.2022 21:15:13
  • Zuletzt bearbeitet 21.11.2024 06:49:19

IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.

  • EPSS 0.13%
  • Veröffentlicht 10.08.2022 20:15:24
  • Zuletzt bearbeitet 21.11.2024 06:34:42

Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues ...

  • EPSS 0.08%
  • Veröffentlicht 11.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 05:56:14

Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.

  • EPSS 0.09%
  • Veröffentlicht 11.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 05:56:08

A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence t...

  • EPSS 0.12%
  • Veröffentlicht 11.05.2022 17:15:08
  • Zuletzt bearbeitet 21.11.2024 05:56:09

In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcod...