cbcvebase.
CVE-2022-23820
published 2023-11-14

CVE-2022-23820: Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

Affected

142 ranges· showing 25
VendorProductVersion rangeFixed in
amd3rd_gen_amd_epyc_processors
amdamd_athlon_3000_series_desktop_processors_with_radeon_graphics_picasso_am4
amdamd_athlon_3000_series_mobile_processors_with_radeon_graphics_pollock
amdamd_epyc_embedded_7003
amdamd_ryzen_3000_series_mobile_processor_with_radeon_graphics_picasso_fp5
amdamd_ryzen_4000_series_mobile_processors_with_radeon_graphics_renoir_fp6
amdamd_ryzen_5000_series_desktop_processor_with_radeon_graphics_cezanne
amdamd_ryzen_5000_series_desktop_processors_vermeer
amdamd_ryzen_5000_series_mobile_processors_with_radeon_graphics_cezanne
amdamd_ryzen_5000_series_mobile_processors_with_radeon_graphics_lucienne
amdamd_ryzen_5000_series_processors_with_radeon_graphics_barcelo
amdamd_ryzen_6000_series_processors_with_radeon_graphics_rembrandt
amdamd_ryzen_7030_series_mobile_processors_with_radeon_graphics_barcelo-r
amdamd_ryzen_7035_series_processors_with_radeon_graphics_rembrandt-r
amdamd_ryzen_threadripper_2000_series_processors_colfax
amdamd_ryzen_threadripper_3000_series_processors_castle_peak_hedt
amdamd_ryzen_threadripper_pro_3000wx_series_processors_chagall_ws
amdamd_ryzen_threadripper_pro_processors_castle_peak_ws_sp3
amdathlon_3015ce_firmware
amdathlon_3015e_firmware
amdryzen_3000_series_desktop_processors_matisse
amdryzen_3_3100_firmware
amdryzen_3_3100_firmware
amdryzen_3_3300u_firmware
amdryzen_3_3300x_firmware