Ryzen 3 3100
Vendor:
First CVE: Nov 16, 2021 · Active for 4 years
38
Total CVEs
More Total CVEs than 97% of tracked products
12.7
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ryzen 3 3100 over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 16, 2021
4 years ago
Most Recent CVE
Nov 14, 2023
986 days ago
CVE Severity & Scoring
Ryzen 3 310038 CVEs
68%
26%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local31 (81.6%)
Network6 (15.8%)
Unknown0 (0.0%)
Physical1 (2.6%)
Adjacent Network0 (0.0%)
Attack Complexity
Low34 (89.5%)
High4 (10.5%)
Unknown0 (0.0%)
User Interaction
None38 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low30 (78.9%)
High2 (5.3%)
None6 (15.8%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (38 CVEs).
38 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-23820CRITICAL Failure to validate the AMD SMM communication buffer
may allow an attacker to corrupt the SMRAM potentially leading to arbitrary
code execution. | Nov 14, 2023 | 9.8 | 30 | NO | NO |
CVE-2021-26392HIGH Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS | Nov 9, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-23821CRITICAL Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
| Nov 14, 2023 | 9.8 | 24 | NO | NO |
CVE-2021-26386HIGH A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code executio | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-26317HIGH Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution. | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-26369HIGH A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses. | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2023-20593MEDIUM An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. | Jul 24, 2023 | 5.5 | 23 | NO | NO |
CVE-2021-26356HIGH A TOCTOU in ASP bootloader may allow an attacker
to tamper with the SPI ROM following data read to memory potentially resulting
in S3 data corruption and information disclosure.
| May 9, 2023 | 7.4 | 23 | NO | NO |
CVE-2022-23825MEDIUM Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. | Jul 14, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-29900MEDIUM Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. | Jul 12, 2022 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (38 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (38 CVEs).
Media Mentions
Signals from CVEs in this product scope (38 CVEs).
Top CNAs Publishing CVEs For Ryzen 3 3100
Top CWEs
Versions
No cataloged versions.