2nd gen amd epyc™
This hub aggregates every CVE we track for 2nd gen amd epyc™, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
19
CVEs tracked
2
Critical
10
High
0
In CISA KEV
Severity distribution
HIGH10MEDIUM6CRITICAL2LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting 2nd gen amd epyc™.
- CVE-2023-20524An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity. 7.5
- CVE-2023-20520Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution. 9.8
- CVE-2021-46775Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution. ...6.8
- CVE-2021-46769Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution. 8.8
- CVE-2021-46764Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service. 7.5
- CVE-2021-46763Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity. 7.5
- CVE-2021-46762Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.3.9
- CVE-2021-26379Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation. 9.8
- CVE-2021-26370Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory w...7.1
- CVE-2021-26408Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.7.1
- CVE-2021-26330AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.5.5
- CVE-2020-12961A potential vulnerability exists in AMD Platform Security Processor (PSP) that may allow an attacker to zero any privileged register on the System Management Network which may lead to bypassing SPI...7.8
- CVE-2020-12954A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.5.5
- CVE-2021-26331AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.7.8
- CVE-2021-26321Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.5.5
Product normalization is registry-driven with AI assist and human review. How it works