AMD
AMD Athlon Gold 3150g Firmware: vulnerabilidades y CVE
AMD Athlon Gold 3150g Firmware tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-23815 | Alta (8.2) | 0.16% | — | 13 ago 2024 | Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution. |
| CVE-2021-26367 | Media (6) | 0.16% | — | 13 ago 2024 | A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability. |
| CVE-2023-20521 | Media (5.7) | 0.26% | — | 14 nov 2023 | TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. |
| CVE-2023-20589 | Media (6.8) | 0.58% | — | 8 ago 2023 | An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary… |
| CVE-2023-20588 | Media (5.5) | 11% | — | 8 ago 2023 | A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. |
| CVE-2023-20555 | Alta (7.8) | 0.32% | — | 8 ago 2023 | Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM. |
| CVE-2021-46794 | Alta (7.5) | 0.62% | — | 9 may 2023 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial… |
| CVE-2021-46792 | Media (5.9) | 0.40% | — | 9 may 2023 | Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event… |
| CVE-2021-46759 | Media (6.1) | 0.28% | — | 9 may 2023 | Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure… |
| CVE-2021-46754 | Crítica (9.1) | 0.56% | — | 9 may 2023 | Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management… |
| CVE-2021-46753 | Crítica (9.1) | 0.56% | — | 9 may 2023 | Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures… |
| CVE-2021-46749 | Alta (7.5) | 0.62% | — | 9 may 2023 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial… |