Home/Product/amd ryzen 5 3500 firmware
Product

amd ryzen 5 3500 firmware

16 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-20533
all versions
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM a
6.1MEDIUM
CVE-2022-23821
all versions
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary
9.8CRITICAL
CVE-2022-23820
all versions
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary c
7.5HIGH
CVE-2021-46774
all versions
Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM a
6.7MEDIUM
CVE-2023-20589
all versions
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection a
6.8MEDIUM
CVE-2023-20593
all versions
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensiti
5.5MEDIUM
CVE-2021-26371
all versions
A compromised or malicious ABL or UApp could send a SHA256 system call to the bootloader, which may result in exposure of ASP memo
5.5MEDIUM
CVE-2021-26356
all versions
A TOCTOU in ASP bootloader may allow an attacker to tamper with the SPI ROM following data read to memory potentially resulting in
7.4HIGH
CVE-2021-26354
all versions
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary
5.5MEDIUM
CVE-2023-20559
< comboam4_v2_pi_1.2.0.6c
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potential
8.8HIGH
CVE-2023-20558
< comboam4_v2_pi_1.2.0.6c
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially le
8.8HIGH
CVE-2022-27672
all versions
When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an
4.7MEDIUM
CVE-2021-26346
all versions
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer ove
5.5MEDIUM
CVE-2021-26392
all versions
Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacke
7.8HIGH
CVE-2020-12931
all versions
Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges
7.8HIGH
CVE-2020-12930
all versions
Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges pot
7.8HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin