Show filters
8 Total Results
Displaying 1-8 of 8
Sort by:
Attacker Value
Unknown

CVE-2023-20521

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
Attacker Value
Unknown

CVE-2022-23821

Disclosure Date: November 14, 2023 (last updated February 13, 2024)
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2022-23820

Disclosure Date: November 14, 2023 (last updated June 18, 2024)
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2023-20555

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
Attacker Value
Unknown

CVE-2020-12930

Disclosure Date: November 08, 2022 (last updated September 17, 2024)
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
Attacker Value
Unknown

CVE-2021-26393

Disclosure Date: November 08, 2022 (last updated September 17, 2024)
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.
Attacker Value
Unknown

CVE-2020-12931

Disclosure Date: November 08, 2022 (last updated September 17, 2024)
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
Attacker Value
Unknown

CVE-2021-26392

Disclosure Date: November 08, 2022 (last updated September 17, 2024)
Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.