Show filters
235 Total Results
Displaying 71-80 of 235
Sort by:
Attacker Value
Unknown

CVE-2021-26398

Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.
Attacker Value
Unknown

CVE-2021-26396

Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
Attacker Value
Unknown

CVE-2021-26355

Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.
Attacker Value
Unknown

CVE-2021-26343

Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
Attacker Value
Unknown

CVE-2021-26328

Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
Attacker Value
Unknown

CVE-2021-26316

Disclosure Date: January 11, 2023 (last updated October 08, 2023)
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
Attacker Value
Unknown

CVE-2022-46143

Disclosure Date: December 13, 2022 (last updated January 14, 2025)
Affected devices do not check the TFTP blocksize correctly. This could allow an authenticated attacker to read from an uninitialized buffer that potentially contains previously allocated data.
0
Attacker Value
Unknown

CVE-2022-46142

Disclosure Date: December 13, 2022 (last updated January 14, 2025)
Affected devices store the CLI user passwords encrypted in flash memory. Attackers with physical access to the device could retrieve the file and decrypt the CLI user passwords.
0
Attacker Value
Unknown

CVE-2022-46140

Disclosure Date: December 13, 2022 (last updated January 14, 2025)
Affected devices use a weak encryption scheme to encrypt the debug zip file. This could allow an authenticated attacker to decrypt the contents of the file and retrieve debug information about the system.
0
Attacker Value
Unknown

CVE-2022-23824

Disclosure Date: November 08, 2022 (last updated February 04, 2024)
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure.