Show filters
14 Total Results
Displaying 1-10 of 14
Sort by:
Attacker Value
Unknown
CVE-2023-31345
Disclosure Date: February 12, 2025 (last updated February 12, 2025)
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-31343
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-31342
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2023-20515
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of integrity, confidentiality, or availability.
0
Attacker Value
Unknown
CVE-2024-21925
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
Improper input validation within the AmdPspP2CmboxV2 driver may allow a privileged attacker to overwrite SMRAM, leading to arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-0179
Disclosure Date: February 11, 2025 (last updated February 12, 2025)
SMM Callout vulnerability within the AmdCpmDisplayFeatureSMM driver could allow locally authenticated attackers to overwrite SMRAM, potentially resulting in arbitrary code execution.
0
Attacker Value
Unknown
CVE-2024-21981
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Improper key usage control in AMD Secure Processor
(ASP) may allow an attacker with local access who has gained arbitrary code
execution privilege in ASP to
extract ASP cryptographic keys, potentially resulting in loss of
confidentiality and integrity.
0
Attacker Value
Unknown
CVE-2023-20518
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.
0
Attacker Value
Unknown
CVE-2022-23817
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space, potentially leading to privilege escalation.
0
Attacker Value
Unknown
CVE-2021-46772
Disclosure Date: August 13, 2024 (last updated August 14, 2024)
Insufficient input validation in the ABL may allow a privileged
attacker with access to the BIOS menu or UEFI shell to tamper with the
structure headers in SPI ROM causing an out of bounds memory read and write,
potentially resulting in memory corruption or denial of service.
0