« Back to list

AMD

AMD Ryzen 5500 Firmware: vulnerabilities and CVEs

AMD Ryzen 5500 Firmware has 11 published vulnerabilities, 0 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs11
Last 12 months0
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2023-20597Medium (5.5)0.18%—Sep 20, 2023
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
CVE-2023-20594Medium (4.4)0.19%—Sep 20, 2023
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
CVE-2021-46794High (7.5)0.62%—May 9, 2023
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial…
CVE-2021-46792Medium (5.9)0.40%—May 9, 2023
Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event…
CVE-2021-46773High (8.8)0.77%—May 9, 2023
Insufficient input validation in ABL may enable a privileged attacker to corrupt ASP memory, potentially resulting in a loss of integrity or code execution.
CVE-2021-46765High (7.5)0.62%—May 9, 2023
Insufficient input validation in ASP may allow an attacker with a compromised SMM to induce out-of-bounds memory reads within the ASP, potentially leading to a denial of service.
CVE-2021-46759Medium (6.1)0.28%—May 9, 2023
Improper syscall input validation in AMD TEE (Trusted Execution Environment) may allow an attacker with physical access and control of a Uapp that runs under the bootloader to reveal the contents of the ASP (AMD Secure…
CVE-2021-46755High (7.5)0.62%—May 9, 2023
Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of…
CVE-2021-46754Critical (9.1)0.56%—May 9, 2023
Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce the bootloader into exposing sensitive information to the SMU (System Management…
CVE-2021-46753Critical (9.1)0.56%—May 9, 2023
Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious Uapp or ABL to map the ASP sensor fusion hub region and overwrite data structures…
CVE-2021-46749High (7.5)0.62%—May 9, 2023
Insufficient bounds checking in ASP (AMD Secure Processor) may allow for an out of bounds read in SMI (System Management Interface) mailbox checksum calculation triggering a data abort, resulting in a potential denial…

Other products by AMD