Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-26328MEDIUMFailure to verify the mode of CPU execution at the time of SNP_INIT may lead to a potential loss of memory integrity for SNP guests. EPSS 0.2%CVE-2021-26404MEDIUMImproper input validation and bounds checking in SEV firmware may leak scratch buffer bytes leading to potential information disclosure. EPSS 0.2%CVE-2021-26343MEDIUMInsufficient validation in ASP BIOS and DRTM commands may allow malicious supervisor x86 software to disclose the contents of sensitive memoEPSS 0.2%CVE-2022-23817HIGHInsufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application toEPSS 0.2%CVE-2024-36310MEDIUMImproper input validation in the SMM communications buffer could allow a privileged attacker to perform an out of bounds read or write to SMEPSS 0.2%CVE-2025-48507HIGHThe security state of the calling processor into Trusted Firmware (TF-A) is not used and could potentially allow non-secure processors accesEPSS 0.2%CVE-2023-20597Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.EPSS 0.2%CVE-2023-31348HIGHA DLL hijacking vulnerability in AMD μProf could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary code EPSS 0.2%CVE-2023-20516LOWImproper handling of insufficiency privileges in the ASP could allow a privileged attacker to modify Translation Map Registers (TMRs) potentEPSS 0.2%CVE-2021-46772LOWInsufficient input validation in the ABL may allow a privileged attacker with access to the BIOS menu or UEFI shell to tamper with the strucEPSS 0.2%CVE-2025-0011LOWImproper removal of sensitive information before storage or transfer in AMD Crash Defender could allow an attacker to obtain kernel address EPSS 0.2%CVE-2021-46791MEDIUMInsufficient input validation during parsing of the System Management Mode (SMM) binary may allow a maliciously crafted SMM executable binarEPSS 0.2%CVE-2025-0003HIGHInadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition potentially resulting in EPSS 0.2%CVE-2023-31342HIGHImproper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execuEPSS 0.2%CVE-2021-26402HIGHInsufficient bounds checking in ASP (AMD Secure Processor) firmware while handling BIOS mailbox commands, may allow an attacker to write parEPSS 0.2%CVE-2023-31345HIGHImproper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execuEPSS 0.2%CVE-2023-31343HIGHImproper input validation in the SMM handler may allow a privileged attacker to overwrite SMRAM, potentially leading to arbitrary code execuEPSS 0.2%CVE-2023-20523MEDIUMTOCTOU in the ASP may allow a physical attacker to write beyond the buffer bounds, potentially leading to a loss of integrity or denial of sEPSS 0.2%CVE-2021-26391HIGHInsufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gaEPSS 0.2%CVE-2023-20599HIGHImproper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) reEPSS 0.2%