5.6 CVE-2024-36350
Enriched by CISA
A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
https://nvd.nist.gov/vuln/detail/CVE-2024-36350
Categories
No category defined
References
af854a3a-2127-422b-91ae-364da2661108
psirt@amd.com
AFFECTED (from MITRE)
| Vendor | Product | Versions |
|---|---|---|
| AMD | AMD EPYC⢠7003 Series Processors |
|
| AMD | AMD EPYC⢠9004 Series Processors |
|
| AMD | AMD EPYC⢠8004 Series Processors |
|
| AMD | AMD EPYC⢠9V64H Processor |
|
| AMD | AMD Ryzen⢠5000 Series Desktop Processors |
|
| AMD | AMD Ryzen⢠5000 Series Desktop Processor with Radeon⢠Graphics |
|
| AMD | AMD Ryzen⢠7000 Series Desktop Processors |
|
| AMD | AMD Ryzen⢠8000 Series Processor with Radeon⢠Graphics |
|
| AMD | AMD Ryzen⢠Threadripper⢠PRO 7000 WX-Series Processors |
|
| AMD | AMD Ryzen⢠6000 Series Processor with Radeon⢠Graphics |
|
| AMD | AMD Ryzen⢠7035 Series Processor with Radeon⢠Graphics |
|
| AMD | AMD Ryzen⢠7000 Series Processors with Radeon⢠Graphics |
|
| AMD | AMD Ryzen⢠7040 Series Processors with Radeon⢠Graphics |
|
| AMD | AMD Ryzen⢠8040 Series Mobile Processors with Radeon⢠Graphics |
|
| AMD | AMD Ryzen⢠7000 Series Mobile Processors |
|
| AMD | AMD EPYC⢠Embedded 7003 Series Processors |
|
| AMD | AMD EPYC⢠Embedded 8004 Series Processors |
|
| AMD | AMD EPYC⢠Embedded 9004 Series Processors |
|
| AMD | AMD Ryzen⢠Embedded 5000 Series Processors |
|
| AMD | AMD Ryzen⢠Embedded 7000 Series Processors |
|
| AMD | AMD Ryzen⢠Embedded V3000 Series Processors |
|
| AMD | AMD EPYC⢠Embedded 97X4 |
|
| AMD | AMD Ryzen⢠5000 Series Processors with Radeon⢠Graphics |
|
| © 2022 The MITRE Corporation. This work is reproduced and distributed with the permission of The MITRE Corporation. | ||
CPE
| cpe | start | end |
|---|
REMEDIATION
EXPLOITS
Exploit-db.com
| id | description | date | |
|---|---|---|---|
| No known exploits | |||
POC Github
| Url |
|---|
| No known exploits |
Other Nist (github, ...)
| Url |
|---|
| No known exploits |
CAPEC
Common Attack Pattern Enumerations and Classifications
| id | description | severity |
|---|---|---|
| No entry | ||
Cybersecurity needs ?
Strengthen software security from the outset with our DevSecOps expertise
Integrate security right from the start of the software development cycle for more robust applications and greater customer confidence.
Our team of DevSecOps experts can help you secure your APIs, data pipelines, CI/CD chains, Docker containers and Kubernetes deployments.
