Show filters
55 Total Results
Displaying 41-50 of 55
Sort by:
Attacker Value
Unknown

CVE-2021-26347

Disclosure Date: May 10, 2022 (last updated October 07, 2023)
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
Attacker Value
Unknown

CVE-2021-26370

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
Attacker Value
Unknown

CVE-2021-26341

Disclosure Date: March 08, 2022 (last updated October 07, 2023)
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
Attacker Value
Unknown

CVE-2021-26401

Disclosure Date: March 08, 2022 (last updated October 07, 2023)
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
Attacker Value
Unknown

CVE-2021-26340

Disclosure Date: December 06, 2021 (last updated October 07, 2023)
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
Attacker Value
Unknown

CVE-2020-12988

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.
Attacker Value
Unknown

CVE-2020-12946

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.
Attacker Value
Unknown

CVE-2021-26320

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
Attacker Value
Unknown

CVE-2021-26321

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.
Attacker Value
Unknown

CVE-2020-12944

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.