CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

amd

epyc_7473x_firmware

55 known vulnerabilities · sorted by CVSS score

CVE-2023-20520
CRITICAL9.8

Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.

amd / epyc_72f3_firmware+62
Network
Published May 9, 2023
Page 1 of 3
CVE-2021-26379
CRITICAL9.8

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

amd / epyc_72f3_firmware+47
Network
Published May 9, 2023
CVE-2021-46756
CRITICAL9.1

Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or ABL to send malformed or invalid syscall to the bootloader resulting in a potential denial of service and loss of integrity.

amd / epyc_72f3_firmware+62
Network
Published May 9, 2023
CVE-2021-46769
HIGH8.8

Insufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code execution.

amd / epyc_72f3_firmware+47
Network
Published May 9, 2023
CVE-2024-21980
HIGH7.9

Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiality and integrity.

amd / epyc_7203_firmware+85
Local
Published Aug 5, 2024
CVE-2021-46771
HIGH7.8

Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.

amd / epyc_7763_firmware+22
Local
Published May 10, 2022
CVE-2021-26353
HIGH7.8

Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.

amd / epyc_7763_firmware+22
Local
Published May 10, 2022
CVE-2021-26324
HIGH7.8

A bug with the SEV-ES TMR may lead to a potential loss of memory integrity for SNP-active VMs.

amd / epyc_7763_firmware+22
Local
Published May 10, 2022
CVE-2023-20524
HIGH7.5

An attacker with a compromised ASP could possibly send malformed commands to an ASP on another CPU, resulting in an out of bounds write, potentially leading to a loss a loss of integrity.

amd / epyc_72f3_firmware+47
Network
Published May 9, 2023
CVE-2021-46763
HIGH7.5

Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.

amd / epyc_72f3_firmware+47
Network
Published May 9, 2023
CVE-2022-23818
HIGH7.5

Insufficient input validation on the model specific register: VM_HSAVE_PA may potentially lead to loss of SEV-SNP guest memory integrity.

amd / epyc_72f3_firmware+22
Network
Published May 9, 2023
CVE-2021-46764
HIGH7.5

Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.

amd / epyc_72f3_firmware+47
Network
Published May 9, 2023
CVE-2023-20578
HIGH7.5

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.

amd / epyc_8024pn_firmware+104
Local
Published Aug 13, 2024
CVE-2021-26356
HIGH7.4

A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.

amd / epyc_7001_firmware+97
Network
Published May 9, 2023
CVE-2021-26344
HIGH7.2

An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.

amd / epyc_7203_firmware+68
Local
Published Aug 13, 2024
CVE-2021-26397
HIGH7.1

Insufficient address validation, may allow an attacker with a compromised ABL and UApp to corrupt sensitive memory locations potentially resulting in a loss of integrity or availability.

amd / epyc_72f3_firmware+22
Local
Published May 9, 2023
CVE-2021-26332
HIGH7.1

Failure to verify SEV-ES TMR is not in MMIO space, SEV-ES FW could result in a potential loss of integrity or availability.

amd / epyc_7763_firmware+22
Local
Published May 10, 2022
CVE-2021-26370
HIGH7.1

Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.

amd / epyc_7763_firmware+48
Local
Published May 10, 2022
CVE-2021-46775
MEDIUM6.8

Improper input validation in ABL may enable an attacker with physical access, to perform arbitrary memory overwrites, potentially leading to a loss of integrity and code execution.

amd / epyc_72f3_firmware+47
Physical
Published May 9, 2023
CVE-2021-46774
MEDIUM6.7

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

amd / epyc_7001_firmware+136
Local
Published Nov 14, 2023