Show filters
9 Total Results
Displaying 1-9 of 9
Sort by:
Attacker Value
Unknown
CVE-2024-21925
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-21924
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
SMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-21981
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Improper key usage control in AMD Secure Processor
(ASP) may allow an attacker with local access who has gained arbitrary code
execution privilege in ASP to
extract ASP cryptographic keys, potentially resulting in loss of
confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2021-46772
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient input validation in the ABL may allow a privileged
attacker with access to the BIOS menu or UEFI shell to tamper with the
structure headers in SPI ROM causing an out of bounds memory read and write,
potentially resulting in memory corruption or denial of service.
0
Attacker Value
Unknown
CVE-2021-46746
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Lack of stack protection exploit mechanisms in ASP Secure OS Trusted Execution Environment (TEE) may allow a privileged attacker with access to AMD signing
keys to c006Frrupt the return address, causing a
stack-based buffer overrun, potentially leading to a denial of service.
0
Attacker Value
Unknown
CVE-2021-26387
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient access controls in ASP kernel may allow a
privileged attacker with access to AMD signing keys and the BIOS menu or UEFI
shell to map DRAM regions in protected areas, potentially leading to a loss of platform integrity.
0
Attacker Value
Unknown
CVE-2023-31315
Disclosure Date: August 12, 2024 (last updated August 13, 2024)
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2022-23829
Disclosure Date: June 18, 2024 (last updated June 19, 2024)
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
0
Attacker Value
Unknown
CVE-2023-20587
Disclosure Date: February 13, 2024 (last updated February 14, 2024)
Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution.
0