CVE-2023-20565

Severity
7.8HIGH
EPSS
0.1%
top 65.31%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14

Description

Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages79 packages

NVDamd/ryzen_3_5100_firmware< comboam4v2_1.2.0.b
NVDamd/ryzen_5_5500_firmware< comboam4v2_1.2.0.b
NVDamd/ryzen_5_7600_firmware< comboam5_1.0.7.0
NVDamd/ryzen_7_5700_firmware< comboam4v2_1.2.0.b
NVDamd/ryzen_7_7700_firmware< comboam5_1.0.7.0

🔴Vulnerability Details

2
GHSA
GHSA-w776-w5x6-c2xf: Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access2023-11-14
CVEList
CVE-2023-20565: Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access2023-11-14
CVE-2023-20565 (HIGH CVSS 7.8) | Insufficient protections in System | cvebase.io