AMD 3015e Firmware
AMD · 8 CVEs
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory con…
Nov 14, 2023
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure…
May 9, 2023
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading t…
May 9, 2023
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause…
May 9, 2023
hw: amd: Insufficient verification in 'LoadModule' may lead to an out-of-bounds write
Nov 9, 2022
hw: amd: Improper handling in ASP drivers leading to loss of integrity
Nov 9, 2022
hw: amd: Insufficient memory cleanup in ASP Trusted Execution Environment (TEE) may poison process contents
Nov 9, 2022
hw: amd: Improper handling in the ASP kernel leading to loss of integrity
Nov 9, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2023-20521 | TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading t… | MEDIUM | 0.26% | Nov 14, 2023 |
| CVE-2021-26371 | A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memory to userspace, potentially… | MEDIUM | 0.19% | May 9, 2023 |
| CVE-2021-26365 | Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limit… | HIGH | 0.57% | May 9, 2023 |
| CVE-2021-26354 | Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initializ… | MEDIUM | 0.18% | May 9, 2023 |
| CVE-2021-26392 | hw: amd: Insufficient verification in 'LoadModule' may lead to an out-of-bounds write | HIGH | 0.27% | Nov 9, 2022 |
| CVE-2020-12930 | hw: amd: Improper handling in ASP drivers leading to loss of integrity | HIGH | 0.26% | Nov 9, 2022 |
| CVE-2021-26393 | hw: amd: Insufficient memory cleanup in ASP Trusted Execution Environment (TEE) may poison process contents | MEDIUM | 0.26% | Nov 9, 2022 |
| CVE-2020-12931 | hw: amd: Improper handling in the ASP kernel leading to loss of integrity | HIGH | 0.26% | Nov 9, 2022 |
Showing 1 to 8 of 8 CVEs