Ryzen 9 4900hs Firmware

Vendor:

First CVE: Mar 11, 2022 · Active for 4 years

8
Total CVEs
More Total CVEs than 87% of tracked products
2.7
Avg CVEs / Year
Higher CVE frequency than 78% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 48% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Ryzen 9 4900hs Firmware over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 11, 2022
4 years ago
Most Recent CVE
Jan 16, 2024
924 days ago

CVE Severity & Scoring

Ryzen 9 4900hs Firmware8 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local5 (62.5%)
Network2 (25.0%)
Unknown0 (0.0%)
Physical1 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (75.0%)
High2 (25.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (62.5%)
High0 (0.0%)
None3 (37.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
Nov 14, 20239.830NONO
Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.
Nov 14, 20239.824NONO
A GPU kernel can read sensitive data from another GPU kernel (even from another user or app) through an optimized GPU memory region called _local memory_ on various architectures.
Jan 16, 20246.523NONO
Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage.
Mar 11, 20226.523NONO
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially lead
Aug 8, 20237.822NONO
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multit
Aug 10, 20225.621NONO
LFENCE/JMP (mitigation V2-2) may not sufficiently mitigate CVE-2017-5715 on some AMD CPUs.
Mar 11, 20225.621NONO
Insufficient validation of SPI flash addresses in the ASP (AMD Secure Processor) bootloader may allow an attacker to read data in memory mapped beyond SPI flash resulting in a pote
Nov 14, 20236.118NONO

Exploit Exposure

Signals from CVEs in this product scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (8 CVEs).

Media Mentions

Signals from CVEs in this product scope (8 CVEs).

Top CNAs Publishing CVEs For Ryzen 9 4900hs Firmware

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
renoirpi-fp6_1.0.0.929.80.8%00