Vulnerabilidades em AMD

458 resultados
Análise Vexday

O portfólio de vulnerabilidades da AMD reúne 443 CVEs catalogadas, com 59 registros surgidos nos últimos 90 dias, indicando um ritmo de descoberta que merece acompanhamento contínuo. A taxa de exploração ativa está abaixo da média geral do catálogo, com zero entradas no CISA KEV, o que sugere pressão operacional imediata menor em comparação com outros fornecedores. No entanto, a CVE mais perigosa atualmente monitorada, CVE-2023-20588, apresenta o maior EPSS observado no conjunto (0,1241), sinalizando probabilidade não negligenciável de exploração e justificando priorização nas rotinas de patch. A falha mais frequente, CWE-20 (validação inadequada de entrada), reflete uma fragilidade estrutural recorrente no código, enquanto as 6 CVEs de severidade crítica e a existência de pelo menos uma prova de conceito pública reforçam a necessidade de gestão ativa mesmo sem exploração confirmada no momento.

CVE-2021-46750LOWFailure to validate the address and size in TEE (Trusted Execution Environment) may allow a malicious x86 attacker to send malformed messageEPSS 0.1%CVE-2025-29952MEDIUMImproper Initialization within the AMD Secure Encrypted Virtualization (SEV) firmware can allow an admin privileged attacker to corrupt RMP EPSS 0.1%CVE-2025-29948MEDIUMImproper access control in AMD Secure Encrypted Virtualization (SEV) firmware could allow a malicious hypervisor to bypass RMP protections, EPSS 0.1%CVE-2025-48506HIGHUncontrolled search paths in Vitis™ Unified installation path on local Windows machines could allow DLL injection into these install paths, EPSS 0.1%CVE-2023-20513LOWAn insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) tEPSS 0.1%CVE-2025-29946MEDIUMInsufficient or Incomplete Data Removal in Hardware Component in SEV firmware doesn't fully flush IOMMU. This can potentially lead to a lossEPSS 0.1%CVE-2025-0036LOWIn AMD Versal Adaptive SoC devices, the incorrect configuration of the SSS during runtime (post-boot) cryptographic operations could cause dEPSS 0.1%CVE-2023-20514HIGHImproper handling of parameters in the AMD Secure Processor (ASP) could allow a privileged attacker to pass an arbitrary memory value to funEPSS 0.1%CVE-2025-54517HIGHOut of bounds write in AMD AMDGV_CMD_GET_DIAG_DATA ioctl handler could allow a local user to escalate privileges via remote code execution.EPSS 0.1%CVE-2021-26387LOWInsufficient access controls in ASP kernel may allow a privileged attacker with access to AMD signing keys and the BIOS menu or UEFI shell tEPSS 0.1%CVE-2025-54502HIGHIncorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (EPSS 0.1%CVE-2024-21923HIGHIncorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially resulting in arbitrary codEPSS 0.1%CVE-2023-20510MEDIUMAn insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially reEPSS 0.1%CVE-2023-20509MEDIUMAn insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, EPSS 0.1%CVE-2024-21922HIGHA DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resulting in arbitrary coEPSS 0.1%CVE-2023-31325HIGHImproper isolation of shared resources on System-on-a-chip (SOC) could a privileged attacker to tamper with the contents of the PSP reservedEPSS 0.1%CVE-2021-26368Insufficient check of the process type in Trusted OS (TOS) may allow an attacker with privileges to enable a lesser privileged process to unEPSS 0.1%CVE-2025-29951HIGHA buffer overflow in the AMD Secure Processor (ASP) bootloader could allow an attacker to overwrite memory, potentially resulting in privileEPSS 0.1%CVE-2025-48514MEDIUMInsufficient Granularity of Access Control in SEV firmware can allow a privileged attacker to create a SEV-ES Guest to attack SNP guest, potEPSS 0.1%CVE-2025-0012MEDIUMImproper handling of overlap between the segmented reverse map table (RMP) and system management mode (SMM) memory could allow a privileged EPSS 0.1%