Modified
Published: 14 Nov 2023, 18:52
Last modified:02 Aug 2024, 09:05

Vulnerability Summary

Overall Risk (default)
low
18/100
CVSS Score
4.6 MEDIUM
v3.1 (nvd)
EPSS Score
0.06% LOW
0% probability +0.02%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

14 Nov 2023, 18:52
Published
Vulnerability first disclosed
02 Aug 2024, 09:05
Last Modified
Vulnerability information updated

Description

Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.

CVSS Metrics

  • v3.1LOWScore: 1.9CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
  • v3.1MEDIUMScore: 4.6CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

EPSS Trends

Current EPSS score: 0.06% Percentile: 19%

Affected Systems

  • amd1st gen amd epyc™ processors

    various

  • amd2nd gen amd epyc™ processors

    various

  • amd3rd gen amd epyc™ processors

    various

  • amdamd epyc™ embedded 3000

    various

  • amdamd epyc™ embedded 7002

    various

  • amdamd epyc™ embedded 7003

    various

  • amdamd ryzen™ threadripper™ 2000 series processors “colfax”

    various

  • amdepyc_7001_firmware

    < naplespi_1.0.0.h

  • amdepyc_7203_firmware

    < milanpi_1.0.0.5

  • amdepyc_7203p_firmware

    < milanpi_1.0.0.5

  • amdepyc_7232p_firmware

    < romepi_1.0.0.d

  • amdepyc_7251_firmware

    < naplespi_1.0.0.h

  • amdepyc_7252_firmware

    < romepi_1.0.0.d

  • amdepyc_7261_firmware

    < naplespi_1.0.0.h

  • amdepyc_7262_firmware

    < romepi_1.0.0.d

  • amdepyc_7272_firmware

    < romepi_1.0.0.d

  • amdepyc_7281_firmware

    < naplespi_1.0.0.h

  • amdepyc_7282_firmware

    < romepi_1.0.0.d

  • amdepyc_72f3_firmware

    < milanpi_1.0.0.5

  • amdepyc_7301_firmware

    < naplespi_1.0.0.h

  • amdepyc_7302_firmware

    < romepi_1.0.0.d

  • amdepyc_7302p_firmware

    < romepi_1.0.0.d

  • amdepyc_7303_firmware

    < milanpi_1.0.0.5

  • amdepyc_7303p_firmware

    < milanpi_1.0.0.5

  • amdepyc_7313_firmware

    < milanpi_1.0.0.5

  • amdepyc_7313p_firmware

    < milanpi_1.0.0.5

  • amdepyc_7343_firmware

    < milanpi_1.0.0.5

  • amdepyc_7351_firmware

    < naplespi_1.0.0.h

  • amdepyc_7351p_firmware

    < naplespi_1.0.0.h

  • amdepyc_7352_firmware

    < romepi_1.0.0.d

  • amdepyc_7371_firmware

    < naplespi_1.0.0.h

  • amdepyc_7373x_firmware

    < milanpi_1.0.0.5

  • amdepyc_73f3_firmware

    < milanpi_1.0.0.5

  • amdepyc_7401_firmware

    < naplespi_1.0.0.h

  • amdepyc_7401p_firmware

    < naplespi_1.0.0.h

  • amdepyc_7402_firmware

    < romepi_1.0.0.d

  • amdepyc_7402p_firmware

    < romepi_1.0.0.d

  • amdepyc_7413_firmware

    < milanpi_1.0.0.5

  • amdepyc_7443_firmware

    < milanpi_1.0.0.5

  • amdepyc_7443p_firmware

    < milanpi_1.0.0.5

  • amdepyc_7451_firmware

    < naplespi_1.0.0.h

  • amdepyc_7452_firmware

    < romepi_1.0.0.d

  • amdepyc_7453_firmware

    < milanpi_1.0.0.5

  • amdepyc_7473x_firmware

    < milanpi_1.0.0.5

  • amdepyc_74f3_firmware

    < milanpi_1.0.0.5

  • amdepyc_7501_firmware

    < naplespi_1.0.0.h

  • amdepyc_7502_firmware

    < romepi_1.0.0.d

  • amdepyc_7502p_firmware

    < romepi_1.0.0.d

  • amdepyc_7513_firmware

    < milanpi_1.0.0.5

  • amdepyc_7532_firmware

    < romepi_1.0.0.d

Showing first 50 affected entries in server-rendered view.

References (3)