CVE-2024-36354
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level.
Published:Sep 6, 2025
Last Modified:Apr 15, 2026
EPS:Sep 6, 2025
EPSS Score:0.00012
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Amd
Product
Athlon
Amd
Athlon
Vendor
Amd
Product
Athlon 3000
Amd
Athlon 3000
Vendor
Amd
Product
Epyc
Amd
Epyc
Vendor
Amd
Product
Epyc 4004
Amd
Epyc 4004
Vendor
Amd
Product
Epyc 7001
Amd
Epyc 7001
Vendor
Amd
Product
Epyc 7002
Amd
Epyc 7002
Vendor
Amd
Product
Epyc 7003
Amd
Epyc 7003
Vendor
Amd
Product
Epyc 8004
Amd
Epyc 8004
Vendor
Amd
Product
Epyc 9004
Amd
Epyc 9004
Vendor
Amd
Product
Epyc Embedded 3000
Amd
Epyc Embedded 3000
Vendor
Amd
Product
Epyc Embedded 7002
Amd
Epyc Embedded 7002
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
