Ryzen
Vendor:
First CVE: Mar 25, 2017 · Active for 9 years
8
Total CVEs
More Total CVEs than 85% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 75% of tracked products
8.0
Avg CVSS
Higher Avg CVSS than 70% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ryzen over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 25, 2017
9 years ago
Most Recent CVE
Oct 13, 2021
1,745 days ago
CVE Severity & Scoring
Ryzen8 CVEs
25%
75%
All CVEs352,231 CVEs
45%
40%
11%
MediumCritical
Attack Vector
Local2 (25.0%)
Network6 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low1 (12.5%)
High7 (87.5%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None6 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-8936CRITICAL The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation. | Mar 22, 2018 | 9.0 | 29 | NO | NO |
CVE-2018-8935CRITICAL The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW. | Mar 22, 2018 | 9.0 | 29 | NO | NO |
CVE-2018-8934CRITICAL The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW. | Mar 22, 2018 | 9.0 | 29 | NO | NO |
CVE-2018-8932CRITICAL The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and RYZENFALL-4. | Mar 22, 2018 | 9.0 | 29 | NO | NO |
CVE-2018-8931CRITICAL The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1. | Mar 22, 2018 | 9.0 | 29 | NO | NO |
CVE-2018-8930CRITICAL The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERKEY-1, MASTERKEY-2, and MASTERKEY-3. | Mar 22, 2018 | 9.0 | 28 | NO | NO |
CVE-2017-7262MEDIUM The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 in | Mar 25, 2017 | 5.5 | 21 | NO | NO |
CVE-2021-26318MEDIUM A timing and power-based side channel attack leveraging the x86 PREFETCH instructions on some AMD CPUs could potentially result in leaked kernel address space information. | Oct 13, 2021 | 4.7 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Ryzen
Top CWEs
Versions
No cataloged versions.