Back to Database
Status published
Medium
CVE-2024-36345
Improper input validation in the AMD OverDrive (AOD) System Management...
Vulnerability Description
Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confidentiality.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-36345
Credits & Attribution
No credits recorded in the NVD database.
References
More from AMD
View All →CVE-2025-66664
Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC...
Medium
4.6
CVE-2025-66660
Insufficient parameter sanitization in TEE SOC Driver could allow an...
Low
1.8
CVE-2025-62628
Unsafe OpenSSL initialization within some AMD optional tools may allow...
High
7
CVE-2025-62627
An untrusted pointer dereference in the ionic cloud driver for...
High
7.2
CVE-2025-62626
Improper handling of insufficient entropy in the AMD CPUs could...
High
7.2
Affected Vendor
Affected Software
AMD EPYC™ 4004, AMD EPYC™ 4005, AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics, AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 7045 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 7000 Series Desktop Processors, AMD Ryzen™ 9000HX Series Mobile Processors, AMD Ryzen™ AI MAX, AMD Ryzen™ AI 300 Series Processors, AMD Ryzen™ Threadripper™ 7000 Processors, AMD Ryzen™ Threadripper™ PRO 7000 WX-Series Processors, AMD Ryzen™ 8000 Series Desktop Processors, AMD Ryzen™ 9000 Series Desktop Processors, AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ Embedded 8000 Series Processors, AMD Ryzen™ Embedded V3000 Series Processors, AMD Ryzen™ Embedded 7000 Series Processors, AMD Ryzen™ Embedded 9000 Series Processors
Vulnerable Versions:
ComboAM5PI 1.1.0.3d, ComboAM5 1.2.0.3j, RembrandtPI-FP7_1.0.0.Bg, PhoenixPI-FP8-FP7_1.2.0.0f, DragonRangeFL1_1.0.0.3l, ComboAM5PI 1.0.0.e, ComboAM5PI 1.1.0.3g, ComboAM5PI 1.2.0.3j, FireRangeFL1PI 1.0.0.0f, StrixHaloPI-FP11_1.0.0.2b, StrixKrackanPI-FP8_1.1.0.0f, StrixKrackanPI-FP8_1.1.0.2e, StormPeakPI-SP6 1.1.0.0k, StormPeakPI-SP6 1.0.0.1m, EmbeddedPhoenixPI-FP7r2_1.0.0.4, Embedded-PI_FP7r2 1012, EmbeddedAM5PI 1.0.0.7
Timeline
Official Publish:
May 15th, 2026
Last Modified:
May 19th, 2026
Added to House:
July 22nd, 2026
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.