CVE Tools

Amd Ryzen™ Embedded 8000 Series Processors

33 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Amd Ryzen™ Embedded 8000 Series Processors, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

Amd Ryzen™ Embedded 8000 Series Processors CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Amd Ryzen™ Embedded 8000 Series Processors CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-093
2025-100
2025-110
2025-120
2026-010
2026-0211
2026-030
2026-041
2026-0518
2026-060
2026-070
2026-080
2026-090

Severity

How the 33 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High330%
  • Medium440%
  • Low330%

Latest CVEs

The 15 most recently published vulnerabilities affecting Amd Ryzen™ Embedded 8000 Series Processors.

  1. CVE-2024-36343Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Me...—
  2. CVE-2025-0044An out-of-bounds read in power management firmware by a malicious local attacker with low privileges could potentially lead to a partial loss of confidentiality and availability.—
  3. CVE-2025-0040Improper access control between the Joint Test Action Group (JTAG) and Advanced Extensible Interface (AXI) could allow an attacker with physical access to read or overwrite the contents of cross-ch...—
  4. CVE-2025-29944A buffer overflow vulnerability within AMD Sensor Fusion Hub Driver can allow a local attacker to write out of bounds, potentially resulting in denial of service or crash—
  5. CVE-2025-29937An out of bounds read within the AMD Platform Management Framework (PMF) could allow an attacker to trigger a read of an arbitrary memory location potentially resulting in loss of availability or c...—
  6. CVE-2025-0028An unchecked return value within the AMD Platform Management Framework (PMF) could allow an attacker to read or modify an arbitrary address potentially resulting in loss of confidentiality, integr...—
  7. CVE-2025-29936Improper input validation within the AMD Platform Management Framework (PMF) could allow an attacker to unmap arbitrary memory pages potentially impacting integrity and availability, or allowing pr...—
  8. CVE-2025-48513Use of uninitialized resource within the AMD Platform Management Framework (PMF) could allow an attacker to read a uninitialized kernel memory resulting in loss of confidentiality or availability.—
  9. CVE-2025-52540An improper input validation vulnerability within the AMD Platform Management Framework (PMF) Driver can allow a local attacker to write Out-of-Bounds, potentially resulting in privilege escalation.—
  10. CVE-2025-48520An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure...—
  11. CVE-2025-48519An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege es...—
  12. CVE-2025-0045Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service—
  13. CVE-2026-0432Incorrect default permissions in the installation directory for the AMD chipset driver could allow an attacker to achieve privilege escalation resulting in arbitrary code execution.—
  14. CVE-2025-48521Improper input validation in the AMD Secure Processor (ASP) PCI driver could allow a local attacker to trigger a Use-After-Free (UAF) condition, potentially resulting in a loss of platform integrit...—
  15. CVE-2025-48512Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary...—

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store