Vulnerabilities
Vulnerable Software
Amd:  >> Epyc 7261 Firmware  Security Vulnerabilities
An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time.
CVSS Score
6.5
EPSS Score
0.001
Published
2022-05-11
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.
CVSS Score
3.3
EPSS Score
0.001
Published
2022-05-11
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
CVSS Score
5.6
EPSS Score
0.001
Published
2022-03-11
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
CVSS Score
6.5
EPSS Score
0.001
Published
2022-03-11
AMD EPYC™ Processors contain an information disclosure vulnerability in the Secure Encrypted Virtualization with Encrypted State (SEV-ES) and Secure Encrypted Virtualization with Secure Nested Paging (SEV-SNP). A local authenticated attacker could potentially exploit this vulnerability leading to leaking guest data by the malicious hypervisor.
CVSS Score
5.5
EPSS Score
0.001
Published
2022-02-04
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
CVSS Score
8.4
EPSS Score
0.001
Published
2021-12-10
Insufficient validation of BIOS image length by ASP Firmware could lead to arbitrary code execution.
CVSS Score
7.8
EPSS Score
0.001
Published
2021-11-16
Insufficient validation of the AMD SEV Signing Key (ASK) in the SEND_START command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
CVSS Score
5.5
EPSS Score
0.001
Published
2021-11-16
Insufficient ID command validation in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP.
CVSS Score
5.5
EPSS Score
0.001
Published
2021-11-16
Failure to flush the Translation Lookaside Buffer (TLB) of the I/O memory management unit (IOMMU) may lead an IO device to write to memory it should not be able to access, resulting in a potential loss of integrity.
CVSS Score
5.5
EPSS Score
0.0
Published
2021-11-16


Contact Us

Shodan ® - All rights reserved