Ryzen 7 2700 Firmware
Vendor:
First CVE: Mar 11, 2022 · Active for 4 years
22
Total CVEs
More Total CVEs than 95% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Ryzen 7 2700 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2022
4 years ago
Most Recent CVE
May 9, 2023
1,176 days ago
CVE Severity & Scoring
Ryzen 7 2700 Firmware22 CVEs
59%
41%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local19 (86.4%)
Network3 (13.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (86.4%)
High3 (13.6%)
Unknown0 (0.0%)
User Interaction
None22 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low21 (95.5%)
High1 (4.5%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-20559HIGH
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
| Apr 2, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-20558HIGH
Insufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalation of privileges.
| Apr 2, 2023 | 8.8 | 26 | NO | NO |
CVE-2021-26316HIGH Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mod | Jan 11, 2023 | 7.8 | 25 | NO | NO |
CVE-2021-26384HIGH A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory re | Jul 14, 2022 | 7.8 | 25 | NO | NO |
CVE-2021-26386HIGH A malicious or compromised UApp or ABL may be used by an attacker to issue a malformed system call to the Stage 2 Bootloader potentially leading to corrupt memory and code executio | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-26317HIGH Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution. | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2021-26369HIGH A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses. | May 12, 2022 | 7.8 | 24 | NO | NO |
CVE-2022-23825MEDIUM Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure. | Jul 14, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-29900MEDIUM Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions. | Jul 12, 2022 | 6.5 | 23 | NO | NO |
CVE-2022-23823MEDIUM A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure | Jun 15, 2022 | 6.5 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (22 CVEs).
Media Mentions
Signals from CVEs in this product scope (22 CVEs).
Top CNAs Publishing CVEs For Ryzen 7 2700 Firmware
Top CWEs
Versions
No cataloged versions.