📦 Epyc 7402 Firmware

by Amd

🔍 What is Epyc 7402 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-46756

CRITICAL CVSS 9.1 May 9, 2023

This vulnerability in AMD Secure Processor bootloader allows attackers with malicious user applications or ABL to send malformed syscalls, potentially causing denial of service and integrity loss. It ...

CVE-2023-20520

CRITICAL CVSS 9.8 May 9, 2023

This vulnerability in AMD ASP Bootloader allows attackers to corrupt return addresses via stack-based buffer overflows, potentially leading to arbitrary code execution. It affects systems with vulnera...

CVE-2021-26379

CRITICAL CVSS 9.8 May 9, 2023

This vulnerability allows an attacker to corrupt SMRAM (System Management RAM) by exploiting insufficient input validation in the SMU (System Management Unit) mailbox data. It can lead to privilege es...

CVE-2023-20578

HIGH CVSS 7.5 Aug 13, 2024

This CVE describes a TOCTOU (Time-Of-Check-Time-Of-Use) vulnerability in AMD System Management Mode (SMM) that could allow an attacker with ring0 privileges and BIOS/UEFI access to modify communicatio...

CVE-2021-46763

HIGH CVSS 7.5 May 9, 2023

This vulnerability allows a privileged attacker to write beyond intended memory bounds in AMD's System Management Unit (SMU), potentially compromising system integrity. It affects systems with vulnera...

CVE-2021-46769

HIGH CVSS 8.8 May 9, 2023

This vulnerability allows a privileged attacker to bypass syscall input validation in AMD's ASP Bootloader, enabling arbitrary DMA copies that can lead to code execution. It affects systems with vulne...

CVE-2021-26356

HIGH CVSS 7.4 May 9, 2023

This vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition in AMD's ASP bootloader that allows an attacker to tamper with SPI ROM data after it's been read to memory. This can lead to S...

CVE-2021-26406

HIGH CVSS 7.5 May 9, 2023

This vulnerability in AMD's Secure Encrypted Virtualization (SEV) and SEV-ES technology allows insufficient validation of Owner's Certificate Authority certificates, potentially causing a host crash a...

CVE-2021-26370

HIGH CVSS 7.1 May 10, 2022

This AMD firmware vulnerability allows attackers with local access to overwrite bootloader memory by exploiting improper address validation in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTR...

CVE-2021-26408

HIGH CVSS 7.1 May 10, 2022

This vulnerability in AMD SEV-legacy firmware allows insufficient validation of elliptic curve points during guest migration. Attackers could potentially compromise guest integrity or confidentiality ...

CVE-2021-26331

HIGH CVSS 7.8 Nov 16, 2021

This vulnerability in AMD System Management Unit (SMU) allows a malicious user to manipulate mailbox entries, potentially leading to arbitrary code execution. It affects AMD processors with vulnerable...

CVE-2020-12944

HIGH CVSS 7.8 Nov 16, 2021

This vulnerability allows attackers to execute arbitrary code by exploiting insufficient validation of BIOS image length in AMD ASP Firmware. It affects systems with vulnerable AMD processors and firm...

CVE-2020-12951

HIGH CVSS 7.0 Nov 16, 2021

A race condition vulnerability in AMD's ASP firmware allows less privileged x86 code to perform System Management Mode operations. This affects AMD processors with vulnerable firmware versions, potent...

CVE-2020-12961

HIGH CVSS 7.8 Nov 16, 2021

This vulnerability in AMD's Platform Security Processor (PSP) allows attackers to manipulate privileged registers on the System Management Network, potentially bypassing SPI ROM protections. This affe...

CVE-2021-26322

HIGH CVSS 7.5 Nov 16, 2021

This vulnerability in AMD platform security processors (PSP) allows potential recovery of encrypted private keys due to insufficient initialization vector (IV) randomness. Attackers could decrypt plat...

CVE-2021-26338

HIGH CVSS 7.5 Nov 16, 2021

CVE-2021-26338 is an improper access control vulnerability in AMD's System Management Unit (SMU) that allows attackers to override performance control tables in DRAM. This could lead to denial of serv...

CVE-2020-12988

HIGH CVSS 7.5 Jun 11, 2021

This vulnerability in AMD integrated chipsets allows a malicious attacker to cause a denial of service by hanging the system during reboot. It affects systems with vulnerable AMD chipsets, potentially...