HP lists them:
http://h22208.www2.hpe.com/eginfolib/securityalerts/AMD/AMD-Flaws.html
https://www.hpe.com/us/en/services/security-vulnerability.html
https://support.hpe.com/hpsc/doc/public/display?docId=emr_na-hpesbhf03841en_us&docLocale=en_US
Government lists them:
https://nvd.nist.gov/vuln/detail/CVE-2018-8933
CVE's have been registered:
https://www.cvedetails.com/vulnerability-list/vendor_id-7043/AMD.html
https://fortiguard.com/psirt/FG-IR-18-046
The related CVEs are:
1. CVE-2018-8930: The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient enforcement of Hardware Validated Boot, aka MASTERKEY-1,
MASTERKEY-2, and MASTERKEY-3.
2. CVE-2018-8931: The AMD Ryzen, Ryzen Pro, and Ryzen Mobile processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-1.
3. CVE-2018-8932: The AMD Ryzen and Ryzen Pro processor chips have insufficient access control for the Secure Processor, aka RYZENFALL-2, RYZENFALL-3, and
RYZENFALL-4.
4. CVE-2018-8933: The AMD EPYC Server processor chips have insufficient access control for protected memory regions, aka FALLOUT-1, FALLOUT-2, and FALLOUT-3.
5. CVE-2018-8934: The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in firmware, aka CHIMERA-FW.
6. CVE-2018-8935: The Promontory chipset, as used in AMD Ryzen and Ryzen Pro platforms, has a backdoor in the ASIC, aka CHIMERA-HW.
7. CVE-2018-8936: The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.
Impact
Execute unauthorized code or commands, Escalation of privilege, Information Disclosure
Affected Products
The following Fortinet products are NOT affected:
FortiOS
FortiAP
FortiAnalyzer
FortiSwitch
References
https://safefirmware.com/amdflaws_whitepaper.pdf
https://safefirmware.com/Whitepaper+Clarification.pdf
https://community.amd.com/community...amd-technical-assessment-of-cts-labs-research
More:
https://www.bleepingcomputer.com/ne...rkey-fallout-and-chimera-cpu-vulnerabilities/