|
196061
|
5.5 |
MEDIUM
Local
|
amd
|
epyc_7003_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_7373x_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware
|
Insufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memory which may result in information disclosure.
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2021-26343
|
2024-11-21 14:56 |
2023-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196062
|
4.4 |
MEDIUM
Local
|
amd
|
epyc_7003_firmware epyc_72f3_firmware epyc_7313_firmware epyc_7313p_firmware epyc_7343_firmware epyc_7373x_firmware epyc_73f3_firmware epyc_7413_firmware epyc_7443_firmware
|
Failure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests.
|
NVD-CWE-noinfo
|
CVE-2021-26328
|
2024-11-21 14:56 |
2023-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196063
|
7.8 |
HIGH
Local
|
amd
|
epyc_7h12_firmware epyc_7f72_firmware epyc_7f52_firmware epyc_7f32_firmware epyc_7742_firmware epyc_7702p_firmware epyc_7702_firmware epyc_7662_firmware epyc_7642_firmware …
|
Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code e…
|
CWE-20
Improper Input Validation
|
CVE-2021-26316
|
2024-11-21 14:56 |
2023-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196064
|
7.8 |
HIGH
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software
|
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s enc…
|
NVD-CWE-noinfo
|
CVE-2021-26360
|
2024-11-21 14:56 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196065
|
5.5 |
MEDIUM
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software radeon_rx_vega_56_firmware radeon_rx_vega_64_firmware ryzen_3_2200ge_firmware ryzen_3_2200g_firmware ryzen_5_2400ge_firmware…
|
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poi…
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2021-26393
|
2024-11-21 14:56 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196066
|
7.8 |
HIGH
Local
|
amd
|
enterprise_driver radeon_pro_software radeon_software radeon_rx_vega_56_firmware radeon_rx_vega_64_firmware ryzen_3_5300ge_firmware ryzen_3_5300g_firmware ryzen_5_5600ge_firmware…
|
Insufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code execution in that TA or the OS/kernel.
|
NVD-CWE-noinfo
|
CVE-2021-26391
|
2024-11-21 14:56 |
2022-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196067
|
7.5 |
HIGH
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A broken access control vulnerability in the FirstReset_handler_func function of spx_restservice allows an attacker to arbitrarily send reboot commands to the BMC, causing a Denial-of-Service (DoS) c…
|
NVD-CWE-Other
|
CVE-2021-26733
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196068
|
5.3 |
MEDIUM
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A broken access control vulnerability in the First_network_func function of spx_restservice allows an attacker to arbitrarily change the network configuration of the BMC. This issue affects: Lanner I…
|
NVD-CWE-Other
|
CVE-2021-26732
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196069
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same…
|
CWE-77 CWE-787
Command Injection Out-of-bounds Write
|
CVE-2021-26731
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196070
|
9.8 |
CRITICAL
Network
|
lannerinc
|
iac-ast2500a_firmware
|
A stack-based buffer overflow vulnerability in a subfunction of the Login_handler_func function of spx_restservice allows an attacker to execute arbitrary code with the same privileges as the server …
|
CWE-787
Out-of-bounds Write
|
CVE-2021-26730
|
2024-11-21 14:56 |
2022-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|