This CPE summary could be partial or incomplete. Please contact us for a detailed listing.

Summary

Detail
Vendor Amd First view 2022-03-11
Product Athlon Silver 3050ge Firmware Last view 2023-05-09
Version Type Os
Update  
Edition  
Language  
Sofware Edition  
Target Software  
Target Hardware  
Other  

Activity : Overall

COMMON PLATFORM ENUMERATION: Repartition per Version

CPE Name Affected CVE
cpe:2.3:o:amd:athlon_silver_3050ge_firmware:picassopi-fp5_1.0.0.e:*:*:*:*:*:*:* 5
cpe:2.3:o:amd:athlon_silver_3050ge_firmware:pollockpi-ft5_1.0.0.4:*:*:*:*:*:*:* 5
cpe:2.3:o:amd:athlon_silver_3050ge_firmware:-:*:*:*:*:*:*:* 3
cpe:2.3:o:amd:athlon_silver_3050ge_firmware:picassopi-fp5_1.0.0.4:*:*:*:*:*:*:* 1

Related : CVE

  Date Alert Description
7.5 2023-05-09 CVE-2021-46794

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

5.9 2023-05-09 CVE-2021-46792

Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service.

6.1 2023-05-09 CVE-2021-46759

Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity.

9.1 2023-05-09 CVE-2021-46754

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity.

9.1 2023-05-09 CVE-2021-46753

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity.

7.5 2023-05-09 CVE-2021-46749

Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service.

7.8 2023-01-11 CVE-2021-26316

Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.

5.6 2022-03-11 CVE-2021-26401

LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.

6.5 2022-03-11 CVE-2021-26341

Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.

CWE : Common Weakness Enumeration

%idName
28% (2) CWE-125 Out-of-bounds Read
28% (2) CWE-20 Improper Input Validation
14% (1) CWE-787 Out-of-bounds Write
14% (1) CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition
14% (1) CWE-212 Improper Cross-boundary Removal of Sensitive Data