AMD
AMD Ryzen 7 4700u Firmware: vulnerabilidades y CVE
AMD Ryzen 7 4700u Firmware tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-20579 | Media (6) | 0.16% | — | 13 feb 2024 | Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability. |
| CVE-2023-4969 | Media (6.5) | 1.2% | — | 16 ene 2024 | A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures. |
| CVE-2022-23821 | Crítica (9.8) | 0.99% | — | 14 nov 2023 | Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution. |
| CVE-2022-23820 | Crítica (9.8) | 0.70% | — | 14 nov 2023 | Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution. |
| CVE-2021-46758 | Media (6.1) | 0.33% | — | 14 nov 2023 | Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a potential loss of availability and… |
| CVE-2023-20555 | Alta (7.8) | 0.32% | — | 8 ago 2023 | Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM. |
| CVE-2022-27672 | Media (4.7) | 0.28% | — | 1 mar 2023 | When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure. |
| CVE-2022-23824 | Media (5.5) | 0.59% | — | 9 nov 2022 | IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information disclosure. |
| CVE-2021-46778 | Media (5.6) | 0.23% | — | 10 ago 2022 | Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the… |
| CVE-2022-23825 | Media (6.5) | 0.78% | — | 14 jul 2022 | Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. |
| CVE-2022-29900 | Media (6.5) | 3.9% | — | 12 jul 2022 | Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. |
| CVE-2022-23823 | Media (6.5) | 1.2% | — | 15 jun 2022 | A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure. |