Show filters
19 Total Results
Displaying 1-10 of 19
Sort by:
Attacker Value
Unknown

CVE-2022-23815

Disclosure Date: August 13, 2024 (last updated December 18, 2024)
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.
Attacker Value
Unknown

CVE-2021-26367

Disclosure Date: August 13, 2024 (last updated December 18, 2024)
A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.
Attacker Value
Unknown

CVE-2023-20589

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 
Attacker Value
Unknown

CVE-2023-20555

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
Attacker Value
Unknown

CVE-2023-20559

Disclosure Date: April 02, 2023 (last updated November 08, 2023)
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
Attacker Value
Unknown

CVE-2023-20558

Disclosure Date: April 02, 2023 (last updated November 08, 2023)
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
Attacker Value
Unknown

CVE-2022-27672

Disclosure Date: March 01, 2023 (last updated November 08, 2023)
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
Attacker Value
Unknown

CVE-2021-26316

Disclosure Date: January 11, 2023 (last updated October 08, 2023)
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
Attacker Value
Unknown

CVE-2020-12930

Disclosure Date: November 08, 2022 (last updated September 17, 2024)
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.
Attacker Value
Unknown

CVE-2021-26393

Disclosure Date: November 08, 2022 (last updated September 17, 2024)
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.