Show filters
73 Total Results
Displaying 11-20 of 73
Sort by:
Attacker Value
Unknown

CVE-2022-23821

Disclosure Date: November 14, 2023 (last updated February 13, 2024)
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2022-23820

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2021-46774

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
Attacker Value
Unknown

CVE-2021-46766

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
Attacker Value
Unknown

CVE-2021-46758

Disclosure Date: November 14, 2023 (last updated November 23, 2023)
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.
Attacker Value
Unknown

CVE-2023-20597

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Attacker Value
Unknown

CVE-2023-20594

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Attacker Value
Unknown

CVE-2023-20589

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 
Attacker Value
Unknown

CVE-2023-20588

Disclosure Date: August 08, 2023 (last updated April 02, 2024)
A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 
Attacker Value
Unknown

CVE-2023-20569

Disclosure Date: August 08, 2023 (last updated April 11, 2024)
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.