CVE-2023-20575
published 2023-07-11CVE-2023-20575: A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a…
PriorityP433medium6.5CVSS 3.1
AVNACLPRLUINSUCHINAN
EPSS
0.80%
52.6th percentile
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 1st_gen_amd_epyc_processors | — | — |
| amd | 2nd_gen_amd_epyc_processors | — | — |
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | 4th_gen_amd_epyc_processors | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mg79-3wxp-f4x4: A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to mo
ghsa_unreviewed·2023-07-11
CVE-2023-20575 [MEDIUM] CWE-203 GHSA-mg79-3wxp-f4x4: A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to mo
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
Red Hat
hw: amd: SEV VM Power Side Channel Security Notice
vendor_redhat·2023-07-11·CVSS 6.5
CVE-2023-20575 [MEDIUM] hw: amd: SEV VM Power Side Channel Security Notice
hw: amd: SEV VM Power Side Channel Security Notice
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
A flaw was found in hw, where a potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM, potentially resulting in a leak of sensitive information.
Mitigation: Please contact AMD technical support for more updates.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: ke
No detection rules found.
No public exploits indexed.
Trailofbits
Cloud cryptography demystified: Google Cloud Platform
blogs_trailofbits·2024-08-05
Cloud cryptography demystified: Google Cloud Platform
This post, the second in our series on cryptography in the cloud, provides an overview of the cloud cryptography services offered within Google Cloud Platform (GCP): when to use them, when not to use them, and important usage considerations. Stay tuned for future posts covering other cloud services.
At Trail of Bits, we frequently encounter products and services that use cloud providers’ cryptography offerings to satisfy their security goals. However, some cloud providers’ cryptography tools and services have opaque names or non-obvious use cases. This guide—informed by Trail of Bits’ extensive auditing experience—dives into the differences between these services and explains important considerations, helping you choose the right solution to enhance your project’s security.
## Introducti
Trailofbits
Cloud cryptography demystified: Google Cloud Platform
blogs_trailofbits·2024-08-05
Cloud cryptography demystified: Google Cloud Platform
This post, the second in our series on cryptography in the cloud, provides an overview of the cloud cryptography services offered within Google Cloud Platform (GCP): when to use them, when not to use them, and important usage considerations. Stay tuned for future posts covering other cloud services.
At Trail of Bits, we frequently encounter products and services that use cloud providers’ cryptography offerings to satisfy their security goals. However, some cloud providers’ cryptography tools and services have opaque names or non-obvious use cases. This guide—informed by Trail of Bits’ extensive auditing experience—dives into the differences between these services and explains important considerations, helping you choose the right solution to enhance your project’s security.
### Introduct
Bugzilla
CVE-2023-20575 hw: amd: SEV VM Power Side Channel Security Notice
bugzilla·2023-06-27·CVSS 6.5
CVE-2023-20575 [MEDIUM] CVE-2023-20575 hw: amd: SEV VM Power Side Channel Security Notice
CVE-2023-20575 hw: amd: SEV VM Power Side Channel Security Notice
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
Refer:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3004.html
Discussion:
Affected Products:
*1st Gen AMD EPYCTM Processors
*2nd Gen AMD EPYCTM Processors
3rd Gen AMD EPYCTM Processors
4th Gen AMD EPYCTM Processors
2023-07-11
Published