CVE Database
/

CVE-2024-36348

Back to search

CVE-2024-36348

Published: Jul 8, 2025

Modified: Nov 4, 2025

PUBLISHED

CVSS v3.1

3.8

LOW

Description

A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage.

VendorProductVersions

AMD

AMD EPYC™ 7002 Series Processors

affected
all

AMD

AMD EPYC™ 7003 Series Processors

affected
all

AMD

AMD EPYC™ 9004 Series Processors

affected
all

AMD

AMD EPYC™ 8004 Series Processors

affected
all

AMD

AMD EPYC™ 4004 Series Processors

affected
all

AMD

AMD EPYC™ 9V64H Processor

affected
all

AMD

AMD Ryzen™ 5000 Series Desktop Processors

affected
all

AMD

AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 3000 Series Desktop Processors

affected
all

AMD

AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 7000 Series Desktop Processors

affected
all

AMD

AMD Ryzen™ 4000 Series Desktop Processor with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 8000 Series Processor with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ Threadripper™ 3000 Series Processors

affected
all

AMD

AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors

affected
all

AMD

AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors

affected
all

AMD

AMD Ryzen™ Threadripper™ PRO 5000WX- Series Desktop Processors

affected
all

AMD

AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 6000 Series Processor with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 7035 Series Processor with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 7000 Series Processors with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 7040 Series Processors with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics

affected
all

AMD

AMD Ryzen™ 7000 Series Mobile Processors

affected
all

AMD

AMD EPYC™ Embedded 7002 Series Processors

affected
all

AMD

AMD EPYC™ Embedded 7003 Series Processors

affected
all

AMD

AMD EPYC™ Embedded 8004 Series Processors

affected
all

AMD

AMD EPYC™ Embedded 9004 Series Processors

affected
all

AMD

AMD Ryzen™ Embedded 5000 Series Processors

affected
all

AMD

AMD Ryzen™ Embedded 7000 Series Processors

affected
all

AMD

AMD Ryzen™ Embedded V2000 Series Processors

affected
all

AMD

AMD Ryzen™ Embedded V3000 Series Processors

affected
all

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Attack Vector

Local

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Changed

Confidentiality

Low

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now