CVE-2023-20515Improper Validation of Specified Quantity in Input in AMD Ryzen Embedded V1000

Severity
5.7MEDIUMNVD
EPSS
0.0%
top 86.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedFeb 11
Latest updateFeb 12

Description

Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of integrity, confidentiality, or availability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:LExploitability: 1.5 | Impact: 3.7

Affected Packages1 packages

CVEListV5amd/amd_ryzen_embedded_v1000No Fix Planned

🔴Vulnerability Details

2
GHSA
GHSA-r7wq-w97f-v622: Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss o2025-02-12
CVEList
CVE-2023-20515: Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss o2025-02-11
CVE-2023-20515 — AMD Ryzen Embedded V1000 vulnerability | cvebase