CVE-2023-20566
published 2023-11-14CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
PriorityP342high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.37%
28.9th percentile
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
Affected
69 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | 4th_gen_amd_epyc_processors | — | — |
| amd | amd_epyc_embedded_7003 | — | — |
| amd | amd_epyc_embedded_9003 | — | — |
| amd | epyc_7203_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7203p_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_72f3_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7303_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7303p_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7313_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7313p_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7343_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7373x_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_73f3_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7413_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7443_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7443p_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7453_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7473x_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_74f3_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7513_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7543_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7543p_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_7573x_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
| amd | epyc_75f3_firmware | < milanpi_1.0.0.b | milanpi_1.0.0.b |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v2hc-cp84-vjqv: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity
ghsa_unreviewed·2023-11-14
CVE-2023-20566 [HIGH] GHSA-v2hc-cp84-vjqv: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity
Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.
OSV
linux-oem-5.14, linux-oem-5.17 vulnerabilities
osv·2023-03-03·CVSS 7.8
CVE-2023-0461 linux-oem-5.14, linux-oem-5.17 vulnerabilities
linux-oem-5.14, linux-oem-5.17 vulnerabilities
It was discovered that the Upper Level Protocol (ULP) subsystem in the
Linux kernel did not properly handle sockets entering the LISTEN state in
certain protocols, leading to a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-0461)
Lee Jones discovered that a use-after-free vulnerability existed in the
Bluetooth implementation in the Linux kernel. A local attacker could use
this to cause a denial of service (system crash) or possibly execute
arbitrary code. (CVE-2022-20566)
It was discovered that the ISDN implementation of the Linux kernel
contained a use-after-free vulnerability. A privileged user could use this
to cause a denial of servi
No detection rules found.
No public exploits indexed.
2023-11-14
Published