amd amd_3015e_firmware CVE Vulnerabilities (8)

CVEs: 8 CPE versions: View versions table

Summary

This page lists publicly disclosed CVE vulnerabilities affecting amd amd_3015e_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.

Showing 18 of 8 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2023-20521 TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service. [email protected] 3.3 0.06% 2023-11-14 2024-11-21
CVE-2021-26371 A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially leading to information disclosure. [email protected] 5.5 0.06% 2023-05-09 2025-01-28
CVE-2021-26365 Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents. [email protected] 8.2 0.51% 2023-05-09 2025-01-28
CVE-2021-26354 Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity. [email protected] 5.5 0.05% 2023-05-09 2025-01-28
CVE-2021-26393 Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality. [email protected] 5.5 0.13% 2022-11-09 2024-11-21
CVE-2021-26392 Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA. [email protected] 7.8 0.14% 2022-11-09 2024-11-21
CVE-2020-12931 Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. [email protected] 7.8 0.08% 2022-11-09 2024-11-21
CVE-2020-12930 Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. [email protected] 7.8 0.08% 2022-11-09 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence