📦 Epyc 7473x Firmware

by Amd

🔍 What is Epyc 7473x Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-46756

CRITICAL CVSS 9.1 May 9, 2023

This vulnerability in AMD Secure Processor bootloader allows attackers with malicious user applications or ABL to send malformed syscalls, potentially causing denial of service and integrity loss. It ...

CVE-2023-20520

CRITICAL CVSS 9.8 May 9, 2023

This vulnerability in AMD ASP Bootloader allows attackers to corrupt return addresses via stack-based buffer overflows, potentially leading to arbitrary code execution. It affects systems with vulnera...

CVE-2021-26379

CRITICAL CVSS 9.8 May 9, 2023

This vulnerability allows an attacker to corrupt SMRAM (System Management RAM) by exploiting insufficient input validation in the SMU (System Management Unit) mailbox data. It can lead to privilege es...

CVE-2023-20578

HIGH CVSS 7.5 Aug 13, 2024

This CVE describes a TOCTOU (Time-Of-Check-Time-Of-Use) vulnerability in AMD System Management Mode (SMM) that could allow an attacker with ring0 privileges and BIOS/UEFI access to modify communicatio...

CVE-2024-21980

HIGH CVSS 7.9 Aug 5, 2024

This vulnerability in AMD Secure Nested Paging (SNP) firmware allows a malicious hypervisor to improperly write to a guest's protected memory regions. This could enable memory corruption attacks affec...

CVE-2021-46763

HIGH CVSS 7.5 May 9, 2023

This vulnerability allows a privileged attacker to write beyond intended memory bounds in AMD's System Management Unit (SMU), potentially compromising system integrity. It affects systems with vulnera...

CVE-2021-46769

HIGH CVSS 8.8 May 9, 2023

This vulnerability allows a privileged attacker to bypass syscall input validation in AMD's ASP Bootloader, enabling arbitrary DMA copies that can lead to code execution. It affects systems with vulne...

CVE-2022-23818

HIGH CVSS 7.5 May 9, 2023

This AMD processor vulnerability allows insufficient input validation on the VM_HSAVE_PA register, potentially enabling attackers to compromise SEV-SNP guest memory integrity. It affects systems using...

CVE-2021-26356

HIGH CVSS 7.4 May 9, 2023

This vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition in AMD's ASP bootloader that allows an attacker to tamper with SPI ROM data after it's been read to memory. This can lead to S...

CVE-2021-46771

HIGH CVSS 7.8 May 10, 2022

This vulnerability in AMD Secure Processor firmware allows insufficient address validation in system calls, potentially enabling arbitrary code execution. It affects systems with AMD processors using ...

CVE-2021-26332

HIGH CVSS 7.1 May 10, 2022

This AMD Secure Encrypted Virtualization-Encrypted State (SEV-ES) firmware vulnerability allows attackers to compromise the integrity or availability of virtual machines by exploiting improper memory ...

CVE-2021-26370

HIGH CVSS 7.1 May 10, 2022

This AMD firmware vulnerability allows attackers with local access to overwrite bootloader memory by exploiting improper address validation in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTR...

CVE-2023-20591

MEDIUM CVSS 6.5 Aug 13, 2024

This AMD processor vulnerability allows improper IOMMU re-initialization during DRTM events, enabling attackers to potentially read or modify hypervisor memory. This affects systems with AMD processor...

CVE-2023-31355

MEDIUM CVSS 6.0 Aug 5, 2024

This vulnerability in AMD Secure Nested Paging (SNP) firmware allows a malicious hypervisor to overwrite a guest's UMC (Unified Memory Controller) seed, potentially enabling memory reading from decomm...