CVE-2023-20555
published 2023-08-08CVE-2023-20555: Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled…
high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Insufficient input validation in
CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting
an arbitrary bit in an attacker-controlled pointer potentially leading to
arbitrary code execution in SMM.
Affected
147 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | athlon_3000_series_desktop_processors_with_radeon_graphics_picasso | — | — |
| amd | athlon_3000_series_mobile_processors_with_radeon_graphics_dali_dali_fp5 | — | — |
| amd | athlon_3000_series_mobile_processors_with_radeon_graphics_pollock | — | — |
| amd | athlon_3015ce_firmware | < pollockpi-ft5_1.0.0.5 | pollockpi-ft5_1.0.0.5 |
| amd | athlon_3015e_firmware | < pollockpi-ft5_1.0.0.5 | pollockpi-ft5_1.0.0.5 |
| amd | athlon_gold_3150c_firmware | < picassopi-fp5_1.0.0.f | picassopi-fp5_1.0.0.f |
| amd | athlon_gold_3150g_firmware | < comboam4piv1_1.0.0.a | comboam4piv1_1.0.0.a |
| amd | athlon_gold_3150g_firmware | < comboam4v2_1.2.0.a | comboam4v2_1.2.0.a |
| amd | athlon_gold_3150ge_firmware | < comboam4piv1_1.0.0.a | comboam4piv1_1.0.0.a |
| amd | athlon_gold_3150ge_firmware | < comboam4v2_1.2.0.a | comboam4v2_1.2.0.a |
| amd | athlon_gold_3150u_firmware | < picassopi-fp5_1.0.0.f | picassopi-fp5_1.0.0.f |
| amd | athlon_gold_pro_3150g_firmware | < comboam4piv1_1.0.0.a | comboam4piv1_1.0.0.a |
| amd | athlon_gold_pro_3150g_firmware | < comboam4v2_1.2.0.a | comboam4v2_1.2.0.a |
| amd | athlon_gold_pro_3150ge_firmware | < comboam4piv1_1.0.0.a | comboam4piv1_1.0.0.a |
| amd | athlon_gold_pro_3150ge_firmware | < comboam4v2_1.2.0.a | comboam4v2_1.2.0.a |
| amd | athlon_pro_300ge_firmware | < comboam4piv1_1.0.0.a | comboam4piv1_1.0.0.a |
| amd | athlon_pro_300ge_firmware | < comboam4v2_1.2.0.a | comboam4v2_1.2.0.a |
| amd | athlon_pro_3045b_firmware | < picassopi-fp5_1.0.0.f | picassopi-fp5_1.0.0.f |
| amd | athlon_pro_3145b_firmware | < picassopi-fp5_1.0.0.f | picassopi-fp5_1.0.0.f |
| amd | athlon_silver_3050c_firmware | < picassopi-fp5_1.0.0.f | picassopi-fp5_1.0.0.f |
| amd | athlon_silver_3050e_firmware | < picassopi-fp5_1.0.0.f | picassopi-fp5_1.0.0.f |
| amd | athlon_silver_3050u_firmware | < picassopi-fp5_1.0.0.f | picassopi-fp5_1.0.0.f |
| amd | ryzen_3000_series_desktop_processors_matisse_am4 | — | — |
| amd | ryzen_3000_series_mobile_processors_with_radeon_graphics_picasso | — | — |
| amd | ryzen_3_3300_firmware | < comboam4_pi_v1_1.0.0.a | comboam4_pi_v1_1.0.0.a |