Show filters
340 Total Results
Displaying 91-100 of 340
Sort by:
Attacker Value
Unknown

CVE-2023-20526

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
Attacker Value
Unknown

CVE-2023-20521

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
Attacker Value
Unknown

CVE-2023-20519

Disclosure Date: November 14, 2023 (last updated November 22, 2023)
A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
Attacker Value
Unknown

CVE-2022-23830

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
SMM configuration may not be immutable, as intended, when SNP is enabled resulting in a potential limited loss of guest memory integrity.
Attacker Value
Unknown

CVE-2022-23821

Disclosure Date: November 14, 2023 (last updated February 13, 2024)
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2022-23820

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2021-46774

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.
Attacker Value
Unknown

CVE-2021-46766

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.
Attacker Value
Unknown

CVE-2021-46758

Disclosure Date: November 14, 2023 (last updated November 23, 2023)
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and integrity.
Attacker Value
Unknown

CVE-2021-46748

Disclosure Date: November 14, 2023 (last updated February 14, 2025)
Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.