Home/Product/amd ryzen 3 3250u firmware
Product

amd ryzen 3 3250u firmware

30 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2022-23815
< picassopi-fp5_1.0.0.e
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, pote
7.5HIGH
CVE-2023-20579
< cezannepi-fp6_1.0.1.0
Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass pr
6.0MEDIUM
CVE-2023-4969
all versions
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory regio
6.5MEDIUM
CVE-2023-20521
< picassopi-fp5_1.0.0.e
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verifi
3.3LOW
CVE-2022-23821
all versions
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary
9.8CRITICAL
CVE-2023-20597
all versions
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
5.5MEDIUM
CVE-2023-20594
all versions
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
4.4MEDIUM
CVE-2021-26371
< picassopi-fp5_1.0.0.d
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memo
5.5MEDIUM
CVE-2021-26365
< picassopi-fp5_1.0.0.d
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of
8.2HIGH
CVE-2021-26354
< picassopi-fp5_1.0.0.d
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary
5.5MEDIUM
CVE-2023-20559
all versions
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potential
8.8HIGH
CVE-2023-20558
all versions
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially le
8.8HIGH
CVE-2022-27672
all versions
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an
4.7MEDIUM
CVE-2021-26346
all versions
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer ove
5.5MEDIUM
CVE-2022-23824
all versions
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information
5.5MEDIUM
CVE-2021-26393
all versions
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attac
5.5MEDIUM
CVE-2021-26392
all versions
Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacke
7.8HIGH
CVE-2020-12931
all versions
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges
7.8HIGH
CVE-2020-12930
all versions
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges pot
7.8HIGH
CVE-2021-46778
all versions
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen
5.6MEDIUM
CVE-2022-23825
all versions
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information
6.5MEDIUM
CVE-2021-26384
all versions
A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structu
7.8HIGH
CVE-2021-26382
< renoirpi-fp6_1.0.0.7
An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irresp
4.4MEDIUM
CVE-2022-29900
all versions
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitect
6.5MEDIUM
CVE-2022-23823
all versions
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing a
6.5MEDIUM
CVE-2021-26388
< comboam4pi_1.0.0.8
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of b
5.5MEDIUM
CVE-2021-26378
< comboam4pi_1.0.0.8
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result i
5.5MEDIUM
CVE-2021-26376
< comboam4pi_1.0.0.8
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denia
5.5MEDIUM
CVE-2021-26375
< comboam4pi_1.0.0.8
Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid a
5.5MEDIUM
CVE-2021-26373
< comboam4pi_1.0.0.8
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in deni
5.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin