Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-26372Insufficient bound checks related to PCIE in the System Management Unit (SMU) may result in access to an invalid address space that could reEPSS 0.2%CVE-2023-31360HIGHIncorrect default permissions in the AMD Integrated Management Technology (AIM-T) Manageability Service installation directory could allow aEPSS 0.2%CVE-2021-26388Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memoEPSS 0.2%CVE-2021-26373Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resoEPSS 0.2%CVE-2021-26376Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resouEPSS 0.2%CVE-2021-26378Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial oEPSS 0.2%CVE-2020-12951Race condition in ASP firmware could allow less privileged x86 code to perform ASP SMM (System Management Mode) operations.EPSS 0.2%CVE-2024-21935MEDIUMImproper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commandsEPSS 0.2%CVE-2021-26363A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenEPSS 0.2%CVE-2021-26349Failure to assign a new report ID to an imported guest may potentially result in an SEV-SNP guest VM being tricked into trusting a dishonestEPSS 0.2%CVE-2023-31356MEDIUMIncomplete system memory cleanup in SEV firmware could allow a privileged attacker to corrupt guest private memory, potentially resulting inEPSS 0.2%CVE-2021-26362A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call which results in mapping sensitive SystemEPSS 0.2%CVE-2021-26364Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which EPSS 0.2%CVE-2021-26346MEDIUMFailure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in tEPSS 0.2%CVE-2021-26398HIGHInsufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AEPSS 0.2%CVE-2025-0033MEDIUMImproper access control within AMD SEV-SNP could allow an admin privileged attacker to write to the RMP during SNP initialization, potentialEPSS 0.2%CVE-2021-46748Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissiEPSS 0.2%CVE-2024-21924HIGHSMM callout vulnerability within the AmdPlatformRasSspSmm driver could allow a ring 0 attacker to modify boot services handlers, potentiallyEPSS 0.2%CVE-2021-26351Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DEPSS 0.2%CVE-2025-54511MEDIUMImproper handling of insufficient privileges in the AMD Secure Processor (ASP) could allow an attacker to provide an input value to a functiEPSS 0.2%