Lucene search

K
cveAMDCVE-2023-20524
HistoryMay 09, 2023 - 7:15 p.m.

CVE-2023-20524

2023-05-0919:15:11
CWE-787
AMD
web.nvd.nist.gov
26
cve-2023-20524
attacker
compromised asp
out of bounds write
integrity loss
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

8

Confidence

High

EPSS

0.001

Percentile

19.4%

An attacker with a compromised ASP could
possibly send malformed commands to an ASP on another CPU, resulting in an out
of bounds write, potentially leading to a loss a loss of integrity.

Affected configurations

Nvd
Node
amdepyc_72f3_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_72f3Match-
Node
amdepyc_7313_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7313Match-
Node
amdepyc_7313p_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7313pMatch-
Node
amdepyc_7343_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7343Match-
Node
amdepyc_7373x_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7373xMatch-
Node
amdepyc_73f3_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_73f3Match-
Node
amdepyc_7413_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7413Match-
Node
amdepyc_7443_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7443Match-
Node
amdepyc_7443p_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7443pMatch-
Node
amdepyc_7453_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7453Match-
Node
amdepyc_7473x_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7473xMatch-
Node
amdepyc_74f3_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_74f3Match-
Node
amdepyc_7513_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7513Match-
Node
amdepyc_7543_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7543Match-
Node
amdepyc_7543p_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7543pMatch-
Node
amdepyc_7573x_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7573xMatch-
Node
amdepyc_75f3_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_75f3Match-
Node
amdepyc_7643_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7643Match-
Node
amdepyc_7663_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7663Match-
Node
amdepyc_7713_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7713Match-
Node
amdepyc_7713p_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7713pMatch-
Node
amdepyc_7763_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7763Match-
Node
amdepyc_7773x_firmwareMatchmilanpi_1.0.0.5
AND
amdepyc_7773xMatch-
Node
amdepyc_7232p_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7232pMatch-
Node
amdepyc_7252_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7252Match-
Node
amdepyc_7262_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7262Match-
Node
amdepyc_7272_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7272Match-
Node
amdepyc_7282_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7282Match-
Node
amdepyc_7302_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7302Match-
Node
amdepyc_7302p_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7302pMatch-
Node
amdepyc_7352_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7352Match-
Node
amdepyc_7402_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7402Match-
Node
amdepyc_7402p_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7402pMatch-
Node
amdepyc_7452_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7452Match-
Node
amdepyc_7502_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7502Match-
Node
amdepyc_7502p_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7502pMatch-
Node
amdepyc_7532_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7532Match-
Node
amdepyc_7542_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7542Match-
Node
amdepyc_7552_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7552Match-
Node
amdepyc_7642_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7642Match-
Node
amdepyc_7662_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7662Match-
Node
amdepyc_7702_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7702Match-
Node
amdepyc_7702p_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7702pMatch-
Node
amdepyc_7742_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7742Match-
Node
amdepyc_7f32_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7f32Match-
Node
amdepyc_7f52_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7f52Match-
Node
amdepyc_7f72_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7f72Match-
Node
amdepyc_7h12_firmwareMatchromepi_1.0.0.c
AND
amdepyc_7h12Match-
VendorProductVersionCPE
amdepyc_72f3_firmwaremilanpi_1.0.0.5cpe:2.3:o:amd:epyc_72f3_firmware:milanpi_1.0.0.5:*:*:*:*:*:*:*
amdepyc_72f3-cpe:2.3:h:amd:epyc_72f3:-:*:*:*:*:*:*:*
amdepyc_7313_firmwaremilanpi_1.0.0.5cpe:2.3:o:amd:epyc_7313_firmware:milanpi_1.0.0.5:*:*:*:*:*:*:*
amdepyc_7313-cpe:2.3:h:amd:epyc_7313:-:*:*:*:*:*:*:*
amdepyc_7313p_firmwaremilanpi_1.0.0.5cpe:2.3:o:amd:epyc_7313p_firmware:milanpi_1.0.0.5:*:*:*:*:*:*:*
amdepyc_7313p-cpe:2.3:h:amd:epyc_7313p:-:*:*:*:*:*:*:*
amdepyc_7343_firmwaremilanpi_1.0.0.5cpe:2.3:o:amd:epyc_7343_firmware:milanpi_1.0.0.5:*:*:*:*:*:*:*
amdepyc_7343-cpe:2.3:h:amd:epyc_7343:-:*:*:*:*:*:*:*
amdepyc_7373x_firmwaremilanpi_1.0.0.5cpe:2.3:o:amd:epyc_7373x_firmware:milanpi_1.0.0.5:*:*:*:*:*:*:*
amdepyc_7373x-cpe:2.3:h:amd:epyc_7373x:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 961

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "packageName": "AGESA",
    "platforms": [
      "x86"
    ],
    "product": "2nd Gen AMD EPYC™ ",
    "vendor": "AMD",
    "versions": [
      {
        "status": "affected",
        "version": "various "
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "packageName": "AGESA",
    "platforms": [
      "x86"
    ],
    "product": "3rd Gen AMD EPYC™ ",
    "vendor": "AMD",
    "versions": [
      {
        "status": "affected",
        "version": "various "
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

8

Confidence

High

EPSS

0.001

Percentile

19.4%

Related for CVE-2023-20524