CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

amd

ryzen_7_3800x_firmware

35 known vulnerabilities · sorted by CVSS score

CVE-2022-23821
CRITICAL9.8

Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.

amd / ryzen_9_3900_firmware+126
Network
Published Nov 14, 2023
Page 1 of 2
CVE-2023-20558
HIGH8.8

Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.

amd / ryzen_7_5700g_firmware+88
Network
Published Apr 2, 2023
CVE-2023-20559
HIGH8.8

Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.

amd / ryzen_7_5700g_firmware+88
Network
Published Apr 2, 2023
CVE-2021-26386
HIGH7.8

A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code execution.

amd / ryzen_3_2200u_firmware+69
Local
Published May 12, 2022
CVE-2021-26369
HIGH7.8

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

amd / radeon_software+49
Local
Published May 12, 2022
CVE-2020-12931
HIGH7.8

Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.

amd / enterprise_driver+106
Local
Published Nov 9, 2022
CVE-2021-26317
HIGH7.8

Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.

amd / radeon_software+73
Local
Published May 12, 2022
CVE-2021-26392
HIGH7.8

Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.

amd / enterprise_driver+102
Local
Published Nov 9, 2022
CVE-2020-12930
HIGH7.8

Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.

amd / enterprise_driver+108
Local
Published Nov 9, 2022
CVE-2022-23820
HIGH7.5

Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

amd / ryzen_9_3900_firmware+123
Local
Published Nov 14, 2023
CVE-2021-26356
HIGH7.4

A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in S3 data corruption and information disclosure.

amd / epyc_7001_firmware+97
Network
Published May 9, 2023
CVE-2021-26366
HIGH7.1

An attacker, who gained elevated privileges via some other vulnerability, may be able to read data from Boot ROM resulting in a loss of system integrity.

amd / radeon_software+62
Local
Published May 12, 2022
CVE-2023-20589
MEDIUM6.8

An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 

amd / ryzen_5_pro_3400g_firmware+121
Physical
Published Aug 8, 2023
CVE-2021-46774
MEDIUM6.7

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

amd / epyc_7001_firmware+136
Local
Published Nov 14, 2023
CVE-2022-23825
MEDIUM6.5

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure.

debian / debian_linux+140
Local
Published Jul 14, 2022
CVE-2021-26341
MEDIUM6.5

Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.

amd / athlon_x4_940_firmware+125
Local
Published Mar 11, 2022
CVE-2022-29900
MEDIUM6.5

Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.

debian / debian_linux+126
Local
Published Jul 12, 2022
CVE-2022-23823
MEDIUM6.5

A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

amd / athlon_x4_750_firmware+141
Network
Published Jun 15, 2022
CVE-2021-26390
MEDIUM6.2

A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of integrity of data.

amd / ryzen_5_2600_firmware+36
Local
Published May 10, 2022
CVE-2023-20533
MEDIUM6.1

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

amd / epyc_7232p_firmware+85
Local
Published Nov 14, 2023