Summary
Detail | |||
---|---|---|---|
Vendor | Amd | First view | 2023-05-09 |
Product | Ryzen 3600x Firmware | Last view | 2023-09-20 |
Version | comboam4pi_1.0.0.9 | Type | Os |
Update | * | ||
Edition | * | ||
Language | * | ||
Sofware Edition | * | ||
Target Software | * | ||
Target Hardware | * | ||
Other | * | ||
CPE Product | cpe:2.3:o:amd:ryzen_3600x_firmware |
Activity : Overall
Related : CVE
Date | Alert | Description | |
---|---|---|---|
5.5 | 2023-09-20 | CVE-2023-20597 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
4.4 | 2023-09-20 | CVE-2023-20594 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
7.5 | 2023-05-09 | CVE-2021-46794 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service. |
6.1 | 2023-05-09 | CVE-2021-46759 | Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure Processor) bootloader accessible memory to a serial port, resulting in a potential loss of integrity. |
7.5 | 2023-05-09 | CVE-2021-46755 | Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service. |
9.1 | 2023-05-09 | CVE-2021-46754 | Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management Unit) resulting in a potential loss of confidentiality and integrity. |
9.1 | 2023-05-09 | CVE-2021-46753 | Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity. |
7.5 | 2023-05-09 | CVE-2021-46749 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service. |
CWE : Common Weakness Enumeration
% | id | Name |
---|---|---|
33% (2) | CWE-665 | Improper Initialization |
33% (2) | CWE-125 | Out-of-bounds Read |
16% (1) | CWE-787 | Out-of-bounds Write |
16% (1) | CWE-20 | Improper Input Validation |