Show filters
33 Total Results
Displaying 1-10 of 33
Sort by:
Attacker Value
Unknown
CVE-2021-26371
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to information disclosure.
0
Attacker Value
Unknown
CVE-2021-26356
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.
0
Attacker Value
Unknown
CVE-2021-26354
Disclosure Date: May 09, 2023 (last updated October 08, 2023)
Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised ABL which may cause
arbitrary memory values to be initialized to zero, potentially leading to a
loss of integrity.
0
Attacker Value
Unknown
CVE-2023-20532
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2023-20531
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2023-20529
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
0
Attacker Value
Unknown
CVE-2023-20528
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
0
Attacker Value
Unknown
CVE-2023-20527
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
0
Attacker Value
Unknown
CVE-2023-20525
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
0
Attacker Value
Unknown
CVE-2023-20523
Disclosure Date: January 11, 2023 (last updated November 08, 2023)
TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.
0