Epyc 7203
Vendor:
First CVE: Nov 14, 2023 · Active for 2 years
16
Total CVEs
More Total CVEs than 92% of tracked products
8.0
Avg CVEs / Year
Higher CVE frequency than 94% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 32% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Epyc 7203 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 14, 2023
2 years ago
Most Recent CVE
Aug 13, 2024
712 days ago
CVE Severity & Scoring
Epyc 720316 CVEs
50%
38%
All CVEs352,719 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local7 (43.8%)
Network7 (43.8%)
Unknown0 (0.0%)
Physical2 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (87.5%)
High2 (12.5%)
Unknown0 (0.0%)
User Interaction
None16 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low1 (6.3%)
High8 (50.0%)
None7 (43.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (16 CVEs).
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-20591CRITICAL Improper re-initialization of IOMMU during the DRTM event
may permit an untrusted platform configuration to persist, allowing an attacker
to read or modify hypervisor memory, poten | Aug 13, 2024 | 10.0 | 30 | NO | NO |
CVE-2024-21978HIGH Improper input validation in SEV-SNP could allow a malicious hypervisor to read or overwrite guest memory potentially leading to data leakage or data corruption. | Aug 5, 2024 | 7.9 | 24 | NO | NO |
CVE-2021-26344HIGH An out of bounds memory write when processing the AMD
PSP1 Configuration Block (APCB) could allow an attacker with access the ability
to modify the BIOS image, and the ability to s | Aug 13, 2024 | 8.2 | 23 | NO | NO |
CVE-2023-20566HIGH Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity. | Nov 14, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-20584MEDIUM IOMMU improperly handles certain special address
ranges with invalid device table entries (DTEs), which may allow an attacker
with privileges and a compromised Hypervisor to
induce | Aug 13, 2024 | 6.0 | 20 | NO | NO |
CVE-2023-20578MEDIUM A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the communications buffer potentially
re | Aug 13, 2024 | 6.4 | 20 | NO | NO |
CVE-2024-21980HIGH Improper restriction of write operations in SNP firmware could allow a malicious hypervisor to potentially overwrite a guest's memory or UMC seed resulting in loss of confidentiali | Aug 5, 2024 | 7.9 | 20 | NO | NO |
CVE-2023-20533HIGH Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service | Nov 14, 2023 | 7.5 | 20 | NO | NO |
CVE-2021-46774HIGH Insufficient DRAM address validation in System
Management Unit (SMU) may allow an attacker to read/write from/to an invalid
DRAM address, potentially resulting in denial-of-service | Nov 14, 2023 | 7.5 | 20 | NO | NO |
CVE-2023-20521MEDIUM TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentia | Nov 14, 2023 | 5.7 | 18 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (16 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (16 CVEs).
Media Mentions
Signals from CVEs in this product scope (16 CVEs).
Top CNAs Publishing CVEs For Epyc 7203
Top CWEs
Versions
No cataloged versions.