Advanced Micro Devices (AMD) EPYC 7743

CPE Details

Advanced Micro Devices (AMD) EPYC 7743
-
2023-01-17
15h59 +00:00
2023-06-20
11h49 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:h:amd:epyc_7743:-:*:*:*:*:*:*:*

Informations

Vendor

amd

Product

epyc_7743

Version

-

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2023-20594 2023-09-20 17h27 +00:00 Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
4.4
Moyen
CVE-2023-20583 2023-08-01 18h00 +00:00 A potential power side-channel vulnerability in AMD processors may allow an authenticated attacker to monitor the CPU power consumption as the data in a cache line changes over time potentially resulting in a leak of sensitive information.
4.7
Moyen
CVE-2023-20532 2023-01-10 20h57 +00:00 Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
5.3
Moyen
CVE-2023-20531 2023-01-10 20h57 +00:00 Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
7.5
Haute
CVE-2023-20530 2023-01-10 20h57 +00:00 Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
7.5
Haute
CVE-2023-20529 2023-01-10 20h57 +00:00 Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
7.5
Haute
CVE-2023-20528 2023-01-10 20h57 +00:00 Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
2.4
Bas
CVE-2023-20527 2023-01-10 20h57 +00:00 Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service.
6.5
Moyen
CVE-2023-20525 2023-01-10 20h57 +00:00 Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service.
6.5
Moyen
CVE-2023-20523 2023-01-10 20h56 +00:00 TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service.
5.7
Moyen
CVE-2021-26402 2023-01-10 20h56 +00:00 Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability.
7.1
Haute
CVE-2021-26398 2023-01-10 20h56 +00:00 Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.
7.8
Haute
CVE-2021-26396 2023-01-10 20h56 +00:00 Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest.
4.4
Moyen
CVE-2021-26355 2023-01-10 20h56 +00:00 Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.
5.5
Moyen
CVE-2021-26343 2023-01-10 20h56 +00:00 Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
5.5
Moyen
CVE-2021-26328 2023-01-10 20h56 +00:00 Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
4.4
Moyen
CVE-2021-26316 2023-01-10 19h46 +00:00 Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.
7.8
Haute