Home/Product/amd ryzen 5 2700 firmware
Product

amd ryzen 5 2700 firmware

11 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-20559
< comboam4v2_pi_1.2.0.6c
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potential
8.8HIGH
CVE-2023-20558
< comboam4v2_pi_1.2.0.6c
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially le
8.8HIGH
CVE-2022-23824
all versions
IBPB may not prevent return branch predictions from being specified by pre-IBPB branch targets leading to a potential information
5.5MEDIUM
CVE-2022-23825
all versions
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information
6.5MEDIUM
CVE-2021-26384
< comboam4v2_pi_1.2.0.6c
A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structu
7.8HIGH
CVE-2022-29900
all versions
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitect
6.5MEDIUM
CVE-2022-23823
all versions
A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing a
6.5MEDIUM
CVE-2021-26388
< comboam4pi_1.0.0.8
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of b
5.5MEDIUM
CVE-2021-26373
< comboam4pi_1.0.0.8
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in deni
5.5MEDIUM
CVE-2021-26390
all versions
A malicious or compromised UApp or ABL may coerce the bootloader into corrupting arbitrary memory potentially leading to loss of i
6.2MEDIUM
CVE-2021-26352
all versions
Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address
5.5MEDIUM
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin