AMD
AMD Ryzen 5500 Firmware: vulnerabilities and CVEs
AMD Ryzen 5500 Firmware has 11 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs11
Last 12 months0
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2023-20597 | Medium (5.5) | 0.18% | — | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
| CVE-2023-20594 | Medium (4.4) | 0.19% | — | Sep 20, 2023 | Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access. |
| CVE-2021-46794 | High (7.5) | 0.62% | — | May 9, 2023 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial… |
| CVE-2021-46792 | Medium (5.9) | 0.40% | — | May 9, 2023 | Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event… |
| CVE-2021-46773 | High (8.8) | 0.77% | — | May 9, 2023 | Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution. |
| CVE-2021-46765 | High (7.5) | 0.62% | — | May 9, 2023 | Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service. |
| CVE-2021-46759 | Medium (6.1) | 0.28% | — | May 9, 2023 | Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure… |
| CVE-2021-46755 | High (7.5) | 0.62% | — | May 9, 2023 | Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of… |
| CVE-2021-46754 | Critical (9.1) | 0.56% | — | May 9, 2023 | Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management… |
| CVE-2021-46753 | Critical (9.1) | 0.56% | — | May 9, 2023 | Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures… |
| CVE-2021-46749 | High (7.5) | 0.62% | — | May 9, 2023 | Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial… |