Modified
Published: 14 Nov 2023, 18:52
Last modified:11 Oct 2024, 18:07

Vulnerability Summary

Overall Risk (default)
medium
30/100
CVSS Score
7.5 HIGH
v3.1 (nvd)
EPSS Score
0.03% LOW
0% probability +0.01%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Nov 2023, 18:52
Published
Vulnerability first disclosed
11 Oct 2024, 18:07
Last Modified
Vulnerability information updated

Description

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

CVSS Metrics

  • v3.1MEDIUMScore: 6.7CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:H/A:L
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.03% Percentile: 10%

Affected Systems

  • amd1st gen amd epyc™ processors

    various

  • amd2nd gen amd epyc™ processors

    various

  • amd3rd gen amd epyc™ processors

    various

  • amd4th gen amd epyc™ processors

    various

  • amdamd epyc™ embedded 3000

    various

  • amdamd epyc™ embedded 7002

    various

  • amdamd epyc™ embedded 7003

    various

  • amdamd ryzen™ embedded 5000

    various

  • amdamd ryzen™ 5000 series desktop processors “vermeer”

    various

  • amdamd ryzen™ threadripper™ 3000 series processors “castle peak” hedt

    various

  • amdamd ryzen™ threadripper™ pro 3000wx series processors “chagall” ws

    various

  • amdamd ryzen™ threadripper™ pro processors “castle peak” ws sp3

    various

  • amdepyc_7001_firmware

    < naplespi_1.0.0.k

  • amdepyc_7203_firmware

    < milanpi_1.0.0.b

  • amdepyc_7203p_firmware

    < milanpi_1.0.0.b

  • amdepyc_7232p_firmware

    < romepi_1.0.0.g

  • amdepyc_7251_firmware

    < naplespi_1.0.0.k

  • amdepyc_7252_firmware

    < romepi_1.0.0.g

  • amdepyc_7261_firmware

    < naplespi_1.0.0.k

  • amdepyc_7262_firmware

    < romepi_1.0.0.g

  • amdepyc_7272_firmware

    < romepi_1.0.0.g

  • amdepyc_7281_firmware

    < naplespi_1.0.0.k

  • amdepyc_7282_firmware

    < romepi_1.0.0.g

  • amdepyc_72f3_firmware

    < milanpi_1.0.0.b

  • amdepyc_7301_firmware

    < naplespi_1.0.0.k

  • amdepyc_7302_firmware

    < romepi_1.0.0.g

  • amdepyc_7302p_firmware

    < romepi_1.0.0.g

  • amdepyc_7303_firmware

    < milanpi_1.0.0.b

  • amdepyc_7303p_firmware

    < milanpi_1.0.0.b

  • amdepyc_7313_firmware

    < milanpi_1.0.0.b

  • amdepyc_7313p_firmware

    < milanpi_1.0.0.b

  • amdepyc_7343_firmware

    < milanpi_1.0.0.b

  • amdepyc_7351_firmware

    < naplespi_1.0.0.k

  • amdepyc_7351p_firmware

    < naplespi_1.0.0.k

  • amdepyc_7352_firmware

    < romepi_1.0.0.g

  • amdepyc_7371_firmware

    < naplespi_1.0.0.k

  • amdepyc_7373x_firmware

    < milanpi_1.0.0.b

  • amdepyc_73f3_firmware

    < milanpi_1.0.0.b

  • amdepyc_7401_firmware

    < naplespi_1.0.0.k

  • amdepyc_7401p_firmware

    < naplespi_1.0.0.k

  • amdepyc_7402_firmware

    < romepi_1.0.0.g

  • amdepyc_7402p_firmware

    < romepi_1.0.0.g

  • amdepyc_7413_firmware

    < milanpi_1.0.0.b

  • amdepyc_7443_firmware

    < milanpi_1.0.0.b

  • amdepyc_7443p_firmware

    < milanpi_1.0.0.b

  • amdepyc_7451_firmware

    < naplespi_1.0.0.k

  • amdepyc_7452_firmware

    < romepi_1.0.0.g

  • amdepyc_7453_firmware

    < milanpi_1.0.0.b

  • amdepyc_7473x_firmware

    < milanpi_1.0.0.b

  • amdepyc_74f3_firmware

    < milanpi_1.0.0.b

Showing first 50 affected entries in server-rendered view.

References (3)