Modified
Published: 14 Nov 2023, 18:52
Last modified:03 Aug 2024, 03:51

Vulnerability Summary

Overall Risk (default)
high
70/100
CVSS Score
9.8 CRITICAL
v3.1 (nvd)
EPSS Score
0.15% LOW
0% probability -0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Nov 2023, 18:52
Published
Vulnerability first disclosed
03 Aug 2024, 03:51
Last Modified
Vulnerability information updated

Description

Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
  • v3.1CRITICALScore: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Trends

Current EPSS score: 0.15% Percentile: 35%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Affected Systems

  • amd3rd gen amd epyc™ processors

    various

  • amdamd athlon™ 3000 series desktop processors with radeon™ graphics “picasso” am4

    various

  • amdamd athlon™ 3000 series mobile processors with radeon™ graphics “pollock”

    various

  • amdamd epyc™ embedded 7003

    various

  • amdamd ryzen™ 3000 series mobile processor with radeon™ graphics “picasso” fp5

    various

  • amdamd ryzen™ 4000 series mobile processors with radeon™ graphics “renoir” fp6

    various

  • amdamd ryzen™ 5000 series desktop processor with radeon™ graphics “cezanne”

    various

  • amdamd ryzen™ 5000 series desktop processors “vermeer”

    various

  • amdamd ryzen™ 5000 series mobile processors with radeon™ graphics “cezanne”

    various

  • amdamd ryzen™ 5000 series mobile processors with radeon™ graphics “lucienne”

    various

  • amdamd ryzen™ 5000 series processors with radeon™ graphics “barcelo”

    various

  • amdamd ryzen™ 6000 series processors with radeon™ graphics "rembrandt"

    various

  • amdamd ryzen™ 7030 series mobile processors with radeon™ graphics “barcelo-r”

    various

  • amdamd ryzen™ 7035 series processors with radeon™ graphics “rembrandt-r”

    various

  • amdamd ryzen™ threadripper™ 2000 series processors “colfax”

    Various

  • amdamd ryzen™ threadripper™ 3000 series processors “castle peak” hedt

    various

  • amdamd ryzen™ threadripper™ pro 3000wx series processors “chagall” ws

    various

  • amdamd ryzen™ threadripper™ pro processors “castle peak” ws sp3

    various

  • amdathlon_3015ce_firmware

    pollockpi-ft5_1.0.0.5

  • amdathlon_3015e_firmware

    pollockpi-ft5_1.0.0.5

  • amdryzen_3_3100_firmware

    comboam4_pi_1.0.0.9 | comboam4_v2_pi_1.2.0.8

  • amdryzen_3_3300u_firmware

    picassopi-fp5_1.0.0.e

  • amdryzen_3_3300x_firmware

    comboam4_pi_1.0.0.9 | comboam4_v2_pi_1.2.0.8

  • amdryzen_3_3350u_firmware

    picassopi-fp5_1.0.0.e

  • amdryzen_3_4300u_firmware

    renoirpi-fp6_1.0.0.9

  • amdryzen_3_5100_firmware

    comboam4v2_pi_1.2.0.8

  • amdryzen_3_5125c_firmware

    cezannepi-fp6_1.0.0.b

  • amdryzen_3_5400u_firmware

    cezannepi-fp6_1.0.0.b

  • amdryzen_3_5425u_firmware

    cezannepi-fp6_1.0.0.b

  • amdryzen_3_7335u_firmware

    rembrandtpi-fp7_1.0.0.2

  • amdryzen_5_3450u_firmware

    picassopi-fp5_1.0.0.e

  • amdryzen_5_3500_firmware

    comboam4_pi_1.0.0.9 | comboam4_v2_pi_1.2.0.8

  • amdryzen_5_3500c_firmware

    picassopi-fp5_1.0.0.e

  • amdryzen_5_3500u_firmware

    picassopi-fp5_1.0.0.e

  • amdryzen_5_3500x_firmware

    comboam4_pi_1.0.0.9 | comboam4_v2_pi_1.2.0.8

  • amdryzen_5_3550h_firmware

    picassopi-fp5_1.0.0.e

  • amdryzen_5_3580u_firmware

    picassopi-fp5_1.0.0.e

  • amdryzen_5_3600_firmware

    comboam4_pi_1.0.0.9 | comboam4_v2_pi_1.2.0.8

  • amdryzen_5_3600x_firmware

    comboam4_pi_1.0.0.9 | comboam4_v2_pi_1.2.0.8

  • amdryzen_5_3600xt_firmware

    comboam4_pi_1.0.0.9 | comboam4_v2_pi_1.2.0.8

  • amdryzen_5_4500u_firmware

    renoirpi-fp6_1.0.0.9

  • amdryzen_5_4600h_firmware

    renoirpi-fp6_1.0.0.9

  • amdryzen_5_4600hs_firmware

    renoirpi-fp6_1.0.0.9

  • amdryzen_5_4600u_firmware

    renoirpi-fp6_1.0.0.9

  • amdryzen_5_4680u_firmware

    renoirpi-fp6_1.0.0.9

  • amdryzen_5_5500_firmware

    comboam4v2_pi_1.2.0.8

  • amdryzen_5_55003xd_firmware

    comboam4v2_pi_1.2.0.8

  • amdryzen_5_5500h_firmware

    cezannepi-fp6_1.0.0.b

  • amdryzen_5_5500x_firmware

    comboam4v2_pi_1.2.0.8

  • amdryzen_5_5560u_firmware

    cezannepi-fp6_1.0.0.b

Showing first 50 affected entries in server-rendered view.

References (3)