Show filters
73 Total Results
Displaying 51-60 of 73
Sort by:
Attacker Value
Unknown

CVE-2021-26370

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
Attacker Value
Unknown

CVE-2021-26408

Disclosure Date: May 06, 2022 (last updated October 07, 2023)
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
Attacker Value
Unknown

CVE-2021-26341

Disclosure Date: March 08, 2022 (last updated October 07, 2023)
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
Attacker Value
Unknown

CVE-2021-26401

Disclosure Date: March 08, 2022 (last updated October 07, 2023)
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
Attacker Value
Unknown

CVE-2021-26340

Disclosure Date: December 06, 2021 (last updated October 07, 2023)
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
Attacker Value
Unknown

CVE-2020-12988

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted.
Attacker Value
Unknown

CVE-2021-26335

Disclosure Date: November 09, 2021 (last updated October 07, 2023)
Improper input and range checking in the AMD Secure Processor (ASP) boot loader image header may allow an attacker to use attacker-controlled values prior to signature validation potentially resulting in arbitrary code execution.
Attacker Value
Unknown

CVE-2021-26320

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
Attacker Value
Unknown

CVE-2020-12946

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.
Attacker Value
Unknown

CVE-2021-26331

Disclosure Date: November 09, 2021 (last updated February 23, 2025)
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.