Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-26370Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allEPSS 0.2%CVE-2020-12946Insufficient input validation in ASP firmware for discrete TPM commands could allow a potential loss of integrity and denial of service.EPSS 0.2%CVE-2022-27677HIGH Failure to validate privileges during installation of AMD Ryzen™ Master may allow an attacker with low privileges to modify files potentialEPSS 0.2%CVE-2024-21938HIGHIncorrect default permissions in the AMD Management Plugin for the Microsoft® System Center Configuration Manager (SCCM) installation directEPSS 0.2%CVE-2023-20560 EPSS 0.2%CVE-2024-36321HIGHUnquoted search path within AIM-T Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbitrarEPSS 0.2%CVE-2025-0035HIGHUnquoted search path within AMD Cloud Manageability Service can allow a local attacker to escalate privileges, potentially resulting in arbiEPSS 0.2%CVE-2021-26360HIGHAn attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This couEPSS 0.2%CVE-2021-26375Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address spaEPSS 0.2%CVE-2024-21944MEDIUMImproper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a sysEPSS 0.2%CVE-2021-26352Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space thaEPSS 0.2%CVE-2021-26348Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory iEPSS 0.2%CVE-2021-26342In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includEPSS 0.2%CVE-2021-26325Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service.EPSS 0.2%CVE-2021-26330AMD System Management Unit (SMU) may experience a heap-based overflow which may result in a loss of resources.EPSS 0.2%CVE-2021-26336Insufficient bounds checking in System Management Unit (SMU) may cause invalid memory accesses/updates that could result in SMU hang and subEPSS 0.2%CVE-2020-12920A potential denial of service issue exists in the AMD Display driver Escape 0x130007 Call handler. An attacker with low privilege could poteEPSS 0.2%CVE-2021-26329AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss EPSS 0.2%CVE-2024-21966HIGHA DLL hijacking vulnerability in the AMD Ryzen™ Master Utility could allow an attacker to achieve privilege escalation, potentially resultiEPSS 0.2%CVE-2024-21949MEDIUMImproper validation of user input in the NPU driver could allow an attacker to provide a buffer with unexpected size, potentially leading toEPSS 0.2%