CVE-2018-8935: Critical severity AMD Ryzen Pro Firmware vulnerability
Published Mar 22, 2018
·Updated
The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.
Affected Software
8 affected components
AMD Ryzen Pro Firmware
AMD Ryzen Pro
AMD Ryzen Firmware
AMD Ryzen
All of the following
AMD Ryzen Pro Firmware
AMD Ryzen Pro
All of the following
AMD Ryzen Firmware
AMD Ryzen
Event History
Mar 22, 2018
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Data Sourced
via NVD·02:29 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2018-8935?
CVE-2018-8935 is considered a high-severity vulnerability due to the presence of a backdoor in the Promontory chipset.
2
How do I fix CVE-2018-8935?
To mitigate CVE-2018-8935, users should update to the latest firmware versions provided by AMD for Ryzen and Ryzen Pro platforms.
3
What systems are affected by CVE-2018-8935?
CVE-2018-8935 affects the Promontory chipset used in AMD Ryzen and Ryzen Pro platforms.
4
What type of vulnerability is CVE-2018-8935?
CVE-2018-8935 is categorized as a hardware vulnerability due to its relation to a backdoor in the ASIC of the Promontory chipset.
5
Is CVE-2018-8935 being actively exploited?
As of now, there are no confirmed reports of active exploitation of CVE-2018-8935, but it remains a significant security concern.