CVE-2023-20526
Vulnerability Summary
Timeline
Description
Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
CVSS Metrics
- v3.1•LOW•Score: 1.9CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N
- v3.1•MEDIUM•Score: 4.6CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Trends
Current EPSS score: 0.06%• Percentile: 19%
Affected Systems
- amd•1st gen amd epyc™ processors
various
- amd•2nd gen amd epyc™ processors
various
- amd•3rd gen amd epyc™ processors
various
- amd•amd epyc™ embedded 3000
various
- amd•amd epyc™ embedded 7002
various
- amd•amd epyc™ embedded 7003
various
- amd•amd ryzen™ threadripper™ 2000 series processors “colfax”
various
- amd•epyc_7001_firmware
< naplespi_1.0.0.h
- amd•epyc_7203_firmware
< milanpi_1.0.0.5
- amd•epyc_7203p_firmware
< milanpi_1.0.0.5
- amd•epyc_7232p_firmware
< romepi_1.0.0.d
- amd•epyc_7251_firmware
< naplespi_1.0.0.h
- amd•epyc_7252_firmware
< romepi_1.0.0.d
- amd•epyc_7261_firmware
< naplespi_1.0.0.h
- amd•epyc_7262_firmware
< romepi_1.0.0.d
- amd•epyc_7272_firmware
< romepi_1.0.0.d
- amd•epyc_7281_firmware
< naplespi_1.0.0.h
- amd•epyc_7282_firmware
< romepi_1.0.0.d
- amd•epyc_72f3_firmware
< milanpi_1.0.0.5
- amd•epyc_7301_firmware
< naplespi_1.0.0.h
- amd•epyc_7302_firmware
< romepi_1.0.0.d
- amd•epyc_7302p_firmware
< romepi_1.0.0.d
- amd•epyc_7303_firmware
< milanpi_1.0.0.5
- amd•epyc_7303p_firmware
< milanpi_1.0.0.5
- amd•epyc_7313_firmware
< milanpi_1.0.0.5
- amd•epyc_7313p_firmware
< milanpi_1.0.0.5
- amd•epyc_7343_firmware
< milanpi_1.0.0.5
- amd•epyc_7351_firmware
< naplespi_1.0.0.h
- amd•epyc_7351p_firmware
< naplespi_1.0.0.h
- amd•epyc_7352_firmware
< romepi_1.0.0.d
- amd•epyc_7371_firmware
< naplespi_1.0.0.h
- amd•epyc_7373x_firmware
< milanpi_1.0.0.5
- amd•epyc_73f3_firmware
< milanpi_1.0.0.5
- amd•epyc_7401_firmware
< naplespi_1.0.0.h
- amd•epyc_7401p_firmware
< naplespi_1.0.0.h
- amd•epyc_7402_firmware
< romepi_1.0.0.d
- amd•epyc_7402p_firmware
< romepi_1.0.0.d
- amd•epyc_7413_firmware
< milanpi_1.0.0.5
- amd•epyc_7443_firmware
< milanpi_1.0.0.5
- amd•epyc_7443p_firmware
< milanpi_1.0.0.5
- amd•epyc_7451_firmware
< naplespi_1.0.0.h
- amd•epyc_7452_firmware
< romepi_1.0.0.d
- amd•epyc_7453_firmware
< milanpi_1.0.0.5
- amd•epyc_7473x_firmware
< milanpi_1.0.0.5
- amd•epyc_74f3_firmware
< milanpi_1.0.0.5
- amd•epyc_7501_firmware
< naplespi_1.0.0.h
- amd•epyc_7502_firmware
< romepi_1.0.0.d
- amd•epyc_7502p_firmware
< romepi_1.0.0.d
- amd•epyc_7513_firmware
< milanpi_1.0.0.5
- amd•epyc_7532_firmware
< romepi_1.0.0.d
Showing first 50 affected entries in server-rendered view.