AMD EPYC 7002
cpe:2.3:h:amd:epyc_7002:*:*:*:*:*:*:*, +1 more
A vulnerability exists in AMD EPYC processors that support Secure Encrypted Virtualization (SEV), specifically during the initialization of Secure Nested Paging (SNP). Improper access control could allow a privileged attacker to write to the reverse map page (RMP), potentially compromising the confidentiality and integrity of guest memory. This issue affects several different versions and ranges of AMD EPYC processors, both server and embedded series.
Exploitation of this vulnerability could lead to unauthorized modifications of the reverse map page, causing a loss of confidentiality and integrity in guest memory during SEV-SNP operations.
Users are advised to update to the latest Platform Initialization (PI) or Secure Encrypted Virtualization (SEV) firmware version. Specific update details can be found in the AMD EPYC Processor Vulnerabilities bulletin.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.