4th gen amd epyc™ processors
This hub aggregates every CVE we track for 4th gen amd epyc™ processors, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.
15
CVEs tracked
0
Critical
3
High
0
In CISA KEV
Severity distribution
MEDIUM8LOW4HIGH3
Monthly trend
0
4
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 15 most recently published vulnerabilities affecting 4th gen amd epyc™ processors.
- CVE-2023-31315Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code...7.5
- CVE-2024-21980Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.7.9
- CVE-2024-21978Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption.6.0
- CVE-2023-31355Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to overwrite a guest's UMC seed potentially allowing reading of memory from a decommissioned guest.6.0
- CVE-2023-20587Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution. 7.1
- CVE-2023-31347Due to a code bug in Secure_TSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of g...4.9
- CVE-2023-31346Failure to initialize memory in SEV Firmware may allow a privileged attacker to access stale data from other guests. 6.0
- CVE-2023-20573Debug Exception Delivery in Secure Nested Paging3.2
- CVE-2023-20566Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.5.3
- CVE-2023-20519A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest in...3.3
- CVE-2021-26345Failure to validate the value in APCB may allow a privileged attacker to tamper with the APCB token to force an out-of-bounds memory read potentially resulting in a denial of service.1.9
- CVE-2021-46774Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.6.7
- CVE-2021-46766Improper clearing of sensitive data in the ASP Bootloader may expose secret keys to a privileged attacker accessing ASP SRAM, potentially leading to a loss of confidentiality.2.5
- CVE-2023-20569 A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled addres...4.7
- CVE-2023-20575 A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SE...6.5
Product normalization is registry-driven with AI assist and human review. How it works