CVE-2020-12967

The lack of nested page table protection in the AMD SEV/SEV-ES feature could potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.2 HIGH
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AMDCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
amdepyc_7232p
-
amdepyc_7251
-
amdepyc_7252
-
amdepyc_7261
-
amdepyc_7262
-
amdepyc_7272
-
amdepyc_7281
-
amdepyc_7282
-
amdepyc_72f3
-
amdepyc_7301
-
amdepyc_7302
-
amdepyc_7302p
-
amdepyc_7313
-
amdepyc_7313p
-
amdepyc_7343
-
amdepyc_7351
-
amdepyc_7351p
-
amdepyc_7352
-
amdepyc_7371
-
amdepyc_73f3
-
amdepyc_7401
-
amdepyc_7401p
-
amdepyc_7402
-
amdepyc_7402p
-
amdepyc_7413
-
amdepyc_7443
-
amdepyc_7443p
-
amdepyc_7451
-
amdepyc_7452
-
amdepyc_7453
-
amdepyc_74f3
-
amdepyc_7501
-
amdepyc_7502
-
amdepyc_7502p
-
amdepyc_7513
-
amdepyc_7532
-
amdepyc_7542
-
amdepyc_7543
-
amdepyc_7543p
-
amdepyc_7551
-
amdepyc_7551p
-
amdepyc_7552
-
amdepyc_75f3
-
amdepyc_7601
-
amdepyc_7642
-
amdepyc_7643
-
amdepyc_7662
-
amdepyc_7663
-
amdepyc_7702
-
amdepyc_7702p
-
amdepyc_7713
-
amdepyc_7713p
-
amdepyc_7742
-
amdepyc_7763
-
amdepyc_7f32
-
amdepyc_7f52
-
amdepyc_7f72
-
amdepyc_7h12
-
amdepyc_embedded_3101
-
amdepyc_embedded_3151
-
amdepyc_embedded_3201
-
amdepyc_embedded_3251
-
amdepyc_embedded_3255
-
amdepyc_embedded_3351
-
amdepyc_embedded_3451
-
𝑥
= Vulnerable software versions