NA - CVE-2023-20509 - An insufficient DRAM address validation in PMFW...
An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity.
NA - CVE-2023-20510 - An insufficient DRAM address validation in PMFW...
An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.
NA - CVE-2023-20512 - A hardcoded AES key in PMFW may result in a...
A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.
NA - CVE-2023-20513 - An insufficient bounds check in PMFW (Power...
An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a...
NA - CVE-2023-20518 - Incomplete cleanup in the ASP may expose the...
Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially...
NA - CVE-2023-20578 - A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may...
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in...
NA - CVE-2023-20584 - IOMMU improperly handles certain special...
IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which may allow an attacker with privileges and a compromised Hypervisor to induce DTE faults to...
NA - CVE-2023-20591 - Improper re-initialization of IOMMU during the...
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting...
NA - CVE-2023-31304 - Improper input validation in SMU may allow an...
Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, potentially leading to a loss of...
NA - CVE-2023-31305 - Generation of weak and predictable...
Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data,...