CVE-2024-36357
MEDIUMAMD Ryzen and EPYC Processors - Exposure of Sensitive Information via Transient Execution
Title source: llmDescription
A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
References (5)
Core 5
Core References
Various Sources
http://xenbits.xen.org/xsa/advisory-471.html
Scores
CVSS v3
5.6
EPSS
0.0010
EPSS Percentile
26.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-1421
Status
published
Products (27)
AMD/AMD EPYC™ 7003 Series Processors
MilanPI 1.0.0.G + OS Updates
AMD/AMD EPYC™ 8004 Series Processors
GenoaPI 1.0.0.E + OS Updates
AMD/AMD EPYC™ 9004 Series Processors
GenoaPI 1.0.0.E + OS Updates
AMD/AMD EPYC™ 9V64H Processor
MI300PI 1.0.0.7 + OS Updates
AMD/AMD EPYC™ Embedded 7003 Series Processors
EmbMilanPI-SP3 1.0.0.A + OS updates
AMD/AMD EPYC™ Embedded 8004 Series Processors
EmbGenoaPI-SP5 1.0.0.9 + OS updates
AMD/AMD EPYC™ Embedded 9004 Series Processors
EmbGenoaPI-SP5 1.0.0.9 + OS updates
AMD/AMD EPYC™ Embedded 97X4
EmbGenoaPI-SP5 1.0.0.9 + OS updates
AMD/AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics
ComboAM4v2PI 1.2.0.E + OS Updates
AMD/AMD Ryzen™ 5000 Series Desktop Processors
ComboAM4v2PI 1.2.0.E + OS Updates
... and 17 more
Published
Jul 08, 2025
Tracked Since
Feb 18, 2026