📦 Epyc 7763 Firmware

by Amd

🔍 What is Epyc 7763 Firmware?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2021-46756

CRITICAL CVSS 9.1 May 9, 2023

This vulnerability in AMD Secure Processor bootloader allows attackers with malicious user applications or ABL to send malformed syscalls, potentially causing denial of service and integrity loss. It ...

CVE-2023-20520

CRITICAL CVSS 9.8 May 9, 2023

This vulnerability in AMD ASP Bootloader allows attackers to corrupt return addresses via stack-based buffer overflows, potentially leading to arbitrary code execution. It affects systems with vulnera...

CVE-2021-26379

CRITICAL CVSS 9.8 May 9, 2023

This vulnerability allows an attacker to corrupt SMRAM (System Management RAM) by exploiting insufficient input validation in the SMU (System Management Unit) mailbox data. It can lead to privilege es...

CVE-2023-20578

HIGH CVSS 7.5 Aug 13, 2024

This CVE describes a TOCTOU (Time-Of-Check-Time-Of-Use) vulnerability in AMD System Management Mode (SMM) that could allow an attacker with ring0 privileges and BIOS/UEFI access to modify communicatio...

CVE-2024-21980

HIGH CVSS 7.9 Aug 5, 2024

This vulnerability in AMD Secure Nested Paging (SNP) firmware allows a malicious hypervisor to improperly write to a guest's protected memory regions. This could enable memory corruption attacks affec...

CVE-2021-46763

HIGH CVSS 7.5 May 9, 2023

This vulnerability allows a privileged attacker to write beyond intended memory bounds in AMD's System Management Unit (SMU), potentially compromising system integrity. It affects systems with vulnera...

CVE-2021-46769

HIGH CVSS 8.8 May 9, 2023

This vulnerability allows a privileged attacker to bypass syscall input validation in AMD's ASP Bootloader, enabling arbitrary DMA copies that can lead to code execution. It affects systems with vulne...

CVE-2022-23818

HIGH CVSS 7.5 May 9, 2023

This AMD processor vulnerability allows insufficient input validation on the VM_HSAVE_PA register, potentially enabling attackers to compromise SEV-SNP guest memory integrity. It affects systems using...

CVE-2021-26356

HIGH CVSS 7.4 May 9, 2023

This vulnerability is a Time-of-Check Time-of-Use (TOCTOU) race condition in AMD's ASP bootloader that allows an attacker to tamper with SPI ROM data after it's been read to memory. This can lead to S...

CVE-2021-46771

HIGH CVSS 7.8 May 10, 2022

This vulnerability in AMD Secure Processor firmware allows insufficient address validation in system calls, potentially enabling arbitrary code execution. It affects systems with AMD processors using ...

CVE-2021-26332

HIGH CVSS 7.1 May 10, 2022

This AMD Secure Encrypted Virtualization-Encrypted State (SEV-ES) firmware vulnerability allows attackers to compromise the integrity or availability of virtual machines by exploiting improper memory ...

CVE-2021-26370

HIGH CVSS 7.1 May 10, 2022

This AMD firmware vulnerability allows attackers with local access to overwrite bootloader memory by exploiting improper address validation in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTR...

CVE-2021-26331

HIGH CVSS 7.8 Nov 16, 2021

This vulnerability in AMD System Management Unit (SMU) allows a malicious user to manipulate mailbox entries, potentially leading to arbitrary code execution. It affects AMD processors with vulnerable...

CVE-2020-12944

HIGH CVSS 7.8 Nov 16, 2021

This vulnerability allows attackers to execute arbitrary code by exploiting insufficient validation of BIOS image length in AMD ASP Firmware. It affects systems with vulnerable AMD processors and firm...

CVE-2020-12951

HIGH CVSS 7.0 Nov 16, 2021

A race condition vulnerability in AMD's ASP firmware allows less privileged x86 code to perform System Management Mode operations. This affects AMD processors with vulnerable firmware versions, potent...

CVE-2020-12961

HIGH CVSS 7.8 Nov 16, 2021

This vulnerability in AMD's Platform Security Processor (PSP) allows attackers to manipulate privileged registers on the System Management Network, potentially bypassing SPI ROM protections. This affe...

CVE-2021-26315

HIGH CVSS 7.8 Nov 16, 2021

This vulnerability in AMD's Platform Security Processor (PSP) boot ROM allows attackers to execute arbitrary code when encrypted firmware images are loaded, due to insufficient integrity verification ...

CVE-2021-26323

HIGH CVSS 7.8 Nov 16, 2021

This vulnerability in AMD processors allows attackers to bypass memory integrity protections when Secure Encrypted Virtualization (SEV) with Secure Nested Paging (SNP) is active. It affects systems us...

CVE-2021-26322

HIGH CVSS 7.5 Nov 16, 2021

This vulnerability in AMD platform security processors (PSP) allows potential recovery of encrypted private keys due to insufficient initialization vector (IV) randomness. Attackers could decrypt plat...

CVE-2021-26338

HIGH CVSS 7.5 Nov 16, 2021

CVE-2021-26338 is an improper access control vulnerability in AMD's System Management Unit (SMU) that allows attackers to override performance control tables in DRAM. This could lead to denial of serv...

CVE-2020-12988

HIGH CVSS 7.5 Jun 11, 2021

This vulnerability in AMD integrated chipsets allows a malicious attacker to cause a denial of service by hanging the system during reboot. It affects systems with vulnerable AMD chipsets, potentially...

CVE-2023-20591

MEDIUM CVSS 6.5 Aug 13, 2024

This AMD processor vulnerability allows improper IOMMU re-initialization during DRTM events, enabling attackers to potentially read or modify hypervisor memory. This affects systems with AMD processor...

CVE-2023-31355

MEDIUM CVSS 6.0 Aug 5, 2024

This vulnerability in AMD Secure Nested Paging (SNP) firmware allows a malicious hypervisor to overwrite a guest's UMC (Unified Memory Controller) seed, potentially enabling memory reading from decomm...