Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.25% | — | AMD Epyc 7001 FirmwareAMD Epyc 7232p FirmwareAMD Epyc 7251 FirmwareAMD Epyc 7261 Firmware+101 | 10/12/2021 | 17/6/2026 | A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM). | |
| Modificada | Media (5.5) | 0.25% | — | AMD Epyc 7601 FirmwareAMD Epyc 7551p FirmwareAMD Epyc 7551 FirmwareAMD Epyc 7501 Firmware+53 | 16/11/2021 | 17/6/2026 | Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP. | |
| Modificada | Media (5.5) | 0.19% | — | AMD Epyc 7601 FirmwareAMD Epyc 7551p FirmwareAMD Epyc 7551 FirmwareAMD Epyc 7501 Firmware+53 | 16/11/2021 | 17/6/2026 | Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP | |
| Modificada | Alta (7.8) | 0.35% | — | AMD Epyc 7601 FirmwareAMD Epyc 7551p FirmwareAMD Epyc 7551 FirmwareAMD Epyc 7501 Firmware+53 | 16/11/2021 | 17/6/2026 | Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution. | |
| Modificada | Media (5.5) | 0.22% | — | AMD Epyc 7601 FirmwareAMD Epyc 7551p FirmwareAMD Epyc 7551 FirmwareAMD Epyc 7501 Firmware+53 | 16/11/2021 | 17/6/2026 | AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources. | |
| Modificada | Alta (7.5) | 1.0% | — | AMD Epyc 7601 FirmwareAMD Epyc 7551p FirmwareAMD Epyc 7551 FirmwareAMD Epyc 7501 Firmware+53 | 16/11/2021 | 17/6/2026 | Persistent platform private key may not be protected with a random IV leading to a potential “two time pad attack”. | |
| Modificada | Media (5.5) | 0.25% | — | AMD Epyc 7601 FirmwareAMD Epyc 7551p FirmwareAMD Epyc 7551 FirmwareAMD Epyc 7501 Firmware+53 | 16/11/2021 | 17/6/2026 | Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity. | |
| Modificada | Alta (7.5) | 1.0% | — | AMD Epyc 7001 FirmwareAMD Epyc 7002 FirmwareAMD Epyc 7003 FirmwareAMD Epyc 7232p Firmware+57 | 11/6/2021 | 17/6/2026 | A potential denial of service (DoS) vulnerability exists in the integrated chipset that may allow a malicious attacker to hang the system when it is rebooted. |