This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Amd First view 2023-05-09
Product Ryzen 5945wx Firmware Last view 2023-09-20
Version Type Os
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:o:amd:ryzen_5945wx_firmware:cezannepi-fp6_1.0.0.b:*:*:*:*:*:*:* 4
cpe:2.3:o:amd:ryzen_5945wx_firmware:cezannepi-fp6_1.0.0.6:*:*:*:*:*:*:* 3
cpe:2.3:o:amd:ryzen_5945wx_firmware:cezannepi-fp6_1.0.0.8:*:*:*:*:*:*:* 3
cpe:2.3:o:amd:ryzen_5945wx_firmware:comboam4v2pi_1.2.0.8:*:*:*:*:*:*:* 2
cpe:2.3:o:amd:ryzen_5945wx_firmware:comboam4v2_pi_1.2.0.8:*:*:*:*:*:*:* 1
cpe:2.3:o:amd:ryzen_5945wx_firmware:comboam4v2_pi_1.2.0.5:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
5.5 2023-09-20 CVE-2023-20597

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

4.4 2023-09-20 CVE-2023-20594

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

7.5 2023-05-09 CVE-2021-46794

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

5.9 2023-05-09 CVE-2021-46792

Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service.

8.8 2023-05-09 CVE-2021-46773

Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution.

7.5 2023-05-09 CVE-2021-46765

Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service.

6.1 2023-05-09 CVE-2021-46759

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity.

9.1 2023-05-09 CVE-2021-46754

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.

9.1 2023-05-09 CVE-2021-46753

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity.

7.5 2023-05-09 CVE-2021-46749

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

CWE : Common Weakness Enumeration

%idName
33% (3) CWE-125 Out-of-bounds Read
22% (2) CWE-665 Improper Initialization
22% (2) CWE-20 Improper Input Validation
11% (1) CWE-787 Out-of-bounds Write
11% (1) CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition