AMD
AMD Ryzen 5 2700 Firmware: vulnerabilidades y CVE
AMD Ryzen 5 2700 Firmware tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20559 | Alta (8.8) | 0.67% | — | 2 abr 2023 | Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges. |
| CVE-2023-20558 | Alta (8.8) | 0.67% | — | 2 abr 2023 | Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges. |
| CVE-2022-23824 | Media (5.5) | 0.59% | — | 9 nov 2022 | IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. |
| CVE-2022-23825 | Media (6.5) | 0.78% | — | 14 jul 2022 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. |
| CVE-2021-26384 | Alta (7.8) | 0.20% | — | 14 jul 2022 | A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI… |
| CVE-2022-29900 | Media (6.5) | 3.9% | — | 12 jul 2022 | Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. |
| CVE-2022-23823 | Media (6.5) | 1.2% | — | 15 jun 2022 | A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure. |
| CVE-2021-26388 | Media (5.5) | 0.22% | — | 11 may 2022 | Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service. |
| CVE-2021-26373 | Media (5.5) | 0.22% | — | 11 may 2022 | Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service. |
| CVE-2021-26390 | Media (6.2) | 0.24% | — | 10 may 2022 | A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data. |
| CVE-2021-26352 | Media (5.5) | 0.22% | — | 10 may 2022 | Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could result in denial of service. |