Amd 3015e
Vendor:
First CVE: Nov 9, 2022 · Active for 3 years
8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Amd 3015e over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 9, 2022
3 years ago
Most Recent CVE
Nov 14, 2023
983 days ago
CVE Severity & Scoring
Amd 3015e8 CVEs
50%
50%
All CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local6 (75.0%)
Network1 (12.5%)
Unknown0 (0.0%)
Physical1 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low6 (75.0%)
High0 (0.0%)
None2 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-26365HIGH Certain size values in firmware binary headers
could trigger out of bounds reads during signature validation, leading to
denial of service or potentially limited leakage of informa | May 9, 2023 | 8.2 | 26 | NO | NO |
CVE-2021-26392HIGH Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS | Nov 9, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-26393MEDIUM Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA | Nov 9, 2022 | 5.5 | 21 | NO | NO |
CVE-2021-26371MEDIUM A compromised or malicious ABL or UApp could
send a SHA256 system call to the bootloader, which may result in exposure of
ASP memory to userspace, potentially leading to informatio | May 9, 2023 | 5.5 | 20 | NO | NO |
CVE-2021-26354MEDIUM Insufficient bounds checking in ASP may allow an
attacker to issue a system call from a compromised ABL which may cause
arbitrary memory values to be initialized to zero, potential | May 9, 2023 | 5.5 | 20 | NO | NO |
CVE-2020-12931HIGH Improper parameters handling in the AMD Secure Processor (ASP) kernel may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. | Nov 9, 2022 | 7.8 | 19 | NO | NO |
CVE-2020-12930HIGH Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity. | Nov 9, 2022 | 7.8 | 19 | NO | NO |
CVE-2023-20521MEDIUM TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentia | Nov 14, 2023 | 5.7 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Amd 3015e
Top CWEs
Versions
No cataloged versions.