Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Jan Wichelmann

Researcher fromUniversity of Lübeck
#19225of 53,632
13.9Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2022-2472
4.9
2022-05-11
Amd · Amd Cpus · CVE-2021-46744
**Name of the Vulnerable Software and Affected Versions** AMD CPUs (affected versions not specified) **Description** The issue is related to the implementation of the SEV-SNP (Secure Nested Paging) protective mechanism for virtual machines running on servers with AMD processors, which is associated with data encryption errors. An attacker with access to a malicious hypervisor may be able to infer data values used in a SEV guest on AMD CPUs by monitoring ciphertext values over time. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2021-16998
9.0
2021-05-13
Amd · Amd Sev/Sev-Es · CVE-2021-26311
**Name of the Vulnerable Software and Affected Versions** AMD SEV/SEV-ES feature (affected versions not specified) **Description** The issue concerns the AMD SEV/SEV-ES feature, where memory can be rearranged in the guest address space without being detected by the attestation mechanism. This could potentially be exploited by a malicious hypervisor to achieve arbitrary code execution within the guest VM, provided a malicious administrator has access to compromise the server hypervisor. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.