Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
475 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.49% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity. | |
| Modificada | Crítica (9.8) | 0.79% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+59 | 9/5/2023 | 17/6/2026 | Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution. | |
| Modificada | Alta (7.5) | 0.50% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+19 | 9/5/2023 | 17/6/2026 | Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity. | |
| Modificada | Media (6.8) | 0.32% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution. | |
| Modificada | Alta (8.8) | 0.78% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution. | |
| Modificada | Alta (7.5) | 0.63% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service. | |
| Modificada | Alta (7.5) | 0.49% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity. | |
| Modificada | Crítica (9.1) | 0.35% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service. | |
| Modificada | Crítica (9.1) | 0.56% | — | AMD Ryzen 6600h FirmwareAMD Ryzen 6600hs FirmwareAMD Ryzen 6600u FirmwareAMD Ryzen 6800h Firmware+62 | 9/5/2023 | 17/6/2026 | Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures leading to a potential loss of confidentiality and integrity. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Ryzen 5300g FirmwareAMD Ryzen 5300ge FirmwareAMD Ryzen 5500 FirmwareAMD Ryzen 5600 Firmware+52 | 9/5/2023 | 17/6/2026 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial of service. | |
| Modificada | Alta (7.5) | 0.42% | — | AMD Epyc 7232p FirmwareAMD Epyc 7252 FirmwareAMD Epyc 7262 FirmwareAMD Epyc 7272 Firmware+36 | 9/5/2023 | 17/6/2026 | Insufficient validation in parsing Owner's Certificate Authority (OCA) certificates in SEV (AMD Secure Encrypted Virtualization) and SEV-ES user application can lead to a host crash potentially resulting in denial of service. | |
| Modificada | Alta (7.1) | 0.18% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+19 | 9/5/2023 | 17/6/2026 | Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability. | |
| Modificada | Crítica (9.8) | 0.68% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation. | |
| Modificada | Media (5.5) | 0.19% | — | AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+124 | 9/5/2023 | 17/6/2026 | A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure. | |
| Modificada | Alta (8.2) | 0.57% | — | AMD Ryzen 5 2400g FirmwareAMD Ryzen 5 2400ge FirmwareAMD Ryzen 3 2200ge FirmwareAMD Ryzen 3 2200g Firmware+50 | 9/5/2023 | 17/6/2026 | Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents. | |
| Modificada | Alta (7.4) | 0.40% | — | AMD Epyc 7001 FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 FirmwareAMD Epyc 7281 Firmware+94 | 9/5/2023 | 17/6/2026 | A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure. | |
| Modificada | Media (5.5) | 0.18% | — | AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+148 | 9/5/2023 | 17/6/2026 | Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity. | |
| Modificada | Alta (8.8) | 0.67% | — | AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600ge Firmware+85 | 2/4/2023 | 17/6/2026 | Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges. | |
| Modificada | Alta (8.8) | 0.67% | — | AMD Ryzen 7 5700g FirmwareAMD Ryzen 7 5700ge FirmwareAMD Ryzen 5 5600g FirmwareAMD Ryzen 5 5600ge Firmware+85 | 2/4/2023 | 17/6/2026 | Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges. | |
| Modificada | Alta (7.8) | 0.22% | — | AMD Ryzen Master | 1/3/2023 | 17/6/2026 | Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentially leading to privilege escalation and code execution by the lower privileged user. | |
| Modificada | Media (4.7) | 0.28% | — | AMD Athlon X4 750 FirmwareAMD Athlon X4 760k FirmwareAMD Athlon X4 830 FirmwareAMD Athlon X4 840 Firmware+161 | 1/3/2023 | 17/6/2026 | When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure. | |
| Modificada | Alta (8.8) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M15 Ryzen Edition R5 FirmwareDell Alienware M17 R5 AMD Firmware+79 | 1/2/2023 | 17/6/2026 | Dell BIOS contains a Stack based buffer overflow vulnerability. A local authenticated attacker could potentially exploit this vulnerability by using an SMI to send larger than expected input to a parameter to gain arbitrary code execution in SMRAM. | |
| Modificada | Alta (7.1) | 0.21% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M15 Ryzen Edition R5 FirmwareDell Alienware M17 R5 AMD Firmware+79 | 1/2/2023 | 17/6/2026 | Dell BIOS contains a heap buffer overflow vulnerability. A local attacker with admin privileges could potentially exploit this vulnerability to perform an arbitrary write to SMRAM during SMM. | |
| Modificada | Media (5.3) | 0.56% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service. |