Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.32% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution. | |
| Modificada | Alta (8.8) | 0.78% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution. | |
| Modificada | Alta (7.5) | 0.63% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service. | |
| Modificada | Alta (7.5) | 0.49% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity. | |
| Modificada | Crítica (9.1) | 0.35% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service. | |
| Modificada | Alta (7.1) | 0.18% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+19 | 9/5/2023 | 17/6/2026 | Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability. | |
| Modificada | Crítica (9.8) | 0.68% | — | AMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+44 | 9/5/2023 | 17/6/2026 | Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation. | |
| Modificada | Media (5.5) | 0.19% | — | AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+124 | 9/5/2023 | 17/6/2026 | A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure. | |
| Modificada | Alta (7.4) | 0.40% | — | AMD Epyc 7001 FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 FirmwareAMD Epyc 7281 Firmware+94 | 9/5/2023 | 17/6/2026 | A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure. | |
| Modificada | Media (5.5) | 0.18% | — | AMD Epyc 7773x FirmwareAMD Epyc 7763 FirmwareAMD Epyc 7713p FirmwareAMD Epyc 7713 Firmware+148 | 9/5/2023 | 17/6/2026 | Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity. | |
| Modificada | Media (5.3) | 0.56% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+20 | 11/1/2023 | 17/6/2026 | Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service. | |
| Modificada | Alta (7.5) | 0.62% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service. | |
| Modificada | Baja (2.4) | 0.24% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality. | |
| Modificada | Media (6.5) | 0.60% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+60 | 11/1/2023 | 17/6/2026 | Improper syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory out-of-bounds, potentially leading to a denial-of-service. | |
| Modificada | Media (6.5) | 0.60% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to read memory outside the bounds of a mapped register potentially leading to a denial of service. | |
| Modificada | Media (5.7) | 0.18% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | TOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of service. | |
| Modificada | Media (5.5) | 0.18% | — | AMD Epyc 7003 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p FirmwareAMD Epyc 7343 Firmware+19 | 11/1/2023 | 17/6/2026 | Improper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. | |
| Modificada | Alta (7.1) | 0.18% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+46 | 11/1/2023 | 17/6/2026 | Insufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write partially-controlled data out-of-bounds to SMM or SEV-ES regions which may lead to a potential loss of integrity and availability. | |
| Modificada | Alta (7.8) | 0.21% | — | AMD Epyc 7h12 FirmwareAMD Epyc 7f72 FirmwareAMD Epyc 7f52 FirmwareAMD Epyc 7f32 Firmware+60 | 11/1/2023 | 17/6/2026 | Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution. | |
| Modificada | Media (4.4) | 0.11% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+20 | 11/1/2023 | 17/6/2026 | Insufficient validation of address mapping to IO in ASP (AMD Secure Processor) may result in a loss of memory integrity in the SNP guest. | |
| Modificada | Media (5.5) | 0.17% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+20 | 11/1/2023 | 17/6/2026 | Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service. | |
| Modificada | Media (5.5) | 0.18% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+20 | 11/1/2023 | 17/6/2026 | Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure. | |
| Modificada | Media (4.4) | 0.18% | — | AMD Epyc 7003 FirmwareAMD Epyc 72f3 FirmwareAMD Epyc 7313 FirmwareAMD Epyc 7313p Firmware+20 | 11/1/2023 | 17/6/2026 | Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests. |