Description
Improper validation of an array index in the AND power Management Firmware could allow a privileged attacker to corrupt AGESA memory potentially leading to a loss of integrity.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected products
- AMD / AMD Athlon™ 3000 Series Desktop Processors with Radeon™ GraphicsComboAM4PI_1.0.0.F – ComboAM4PI_1.0.0.F
- AMD / AMD Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsPicasso-FP5 1.0.1.2 – Picasso-FP5 1.0.1.2
- AMD / AMD Ryzen™ 3000 Series Desktop ProcessorsComboAM4PI_1.0.0.F – ComboAM4PI_1.0.0.F
- AMD / AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ GraphicsPicasso-FP5 1.0.1.2 – Picasso-FP5 1.0.1.2
- AMD / AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ GraphicsRenoirPI-FP6_1.0.0.E – RenoirPI-FP6_1.0.0.E
- AMD / AMD Ryzen™ 5000 Series Desktop ProcessorsComboAM4PI_1.0.0.F – ComboAM4PI_1.0.0.F
- AMD / AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ GraphicsCezannePI-FP6_1.0.1.1 – CezannePI-FP6_1.0.1.1
- AMD / AMD Ryzen™ 6000 Series Processors with Radeon™ GraphicsRembrandtPI-FP7_1.0.0.B – RembrandtPI-FP7_1.0.0.B
- AMD / AMD Ryzen™ 7000 Series Desktop ProcessorsComboAM5 1.2.0.0 – ComboAM5 1.2.0.0
- AMD / AMD Ryzen™ 7020 Series Processors with Radeon™ GraphicsMendocinoPI-FT6_1.0.0.6 – MendocinoPI-FT6_1.0.0.6
- AMD / AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ GraphicsCezannePI-FP6_1.0.1.1 – CezannePI-FP6_1.0.1.1
- AMD / AMD Ryzen™ 7035 Series Processors with Radeon™ GraphicsRembrandtPI-FP7_1.0.0.B – RembrandtPI-FP7_1.0.0.B
- AMD / AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ GraphicsDragonRangeFL1 1.0.0.3d – DragonRangeFL1 1.0.0.3d
- AMD / AMD Ryzen™ 8000 Series Desktop ProcessorsComboAM5 1.2.0.0 – ComboAM5 1.2.0.0
- AMD / AMD Ryzen™ Embedded 5000 Series ProcessorsEmbAM4PI 1.0.0.7 – EmbAM4PI 1.0.0.7
- AMD / AMD Ryzen™ Embedded 7000 Series ProcessorsEmbeddedAM5PI 1.0.0.3 – EmbeddedAM5PI 1.0.0.3
- AMD / AMD Ryzen™ Embedded R1000 Series ProcessorsEmbeddedPI-FP5 1.2.0.E – EmbeddedPI-FP5 1.2.0.E
- AMD / AMD Ryzen™ Embedded R2000 Series ProcessorsEmbeddedR2KPI-FP5 1005 – EmbeddedR2KPI-FP5 1005
- AMD / AMD Ryzen™ Embedded V1000 Series ProcessorsEmbeddedPI-FP5 1.2.0.E – EmbeddedPI-FP5 1.2.0.E
- AMD / AMD Ryzen™ Embedded V2000 Series ProcessorsEmbeddedPI-FP6_1.0.0.B – EmbeddedPI-FP6_1.0.0.B
- AMD / AMD Ryzen™ Embedded V3000 Series ProcessorsEmbedded-PI_FP7r2 100A – Embedded-PI_FP7r2 100A
- AMD / AMD Ryzen™ Threadripper™ 3000 ProcessorsCastlePeakPI-SP3r3 1.0.0.C – CastlePeakPI-SP3r3 1.0.0.C
- AMD / AMD Ryzen™ Threadripper™ PRO 3000 WX-Series ProcessorsChagallWSPI-sWRX8-1.0.0.9 – ChagallWSPI-sWRX8-1.0.0.9
- AMD / AMD Ryzen™ Threadripper™ PRO 3000 WX-Series ProcessorsCastlePeakWSPI-sWRX8 1.0.0.E – CastlePeakWSPI-sWRX8 1.0.0.E
- AMD / AMD Ryzen™ Threadripper™ PRO 5000 WX-Series ProcessorsChagallWSPI-sWRX8-1.0.0.9 – ChagallWSPI-sWRX8-1.0.0.9
- AMD / Renoir Cezanne Raven Ridge Raven Ridge 2 Picasso Summit Pinnacle Ridge Matisse VermeerComboAM4v2PI_1.2.0.D – ComboAM4v2PI_1.2.0.D