CVE-2023-20579
published 2024-02-13CVE-2023-20579: Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially…
PriorityP425medium6CVSS 3.1
AVLACLPRHUINSUCNIHAH
EPSS
0.16%
5.9th percentile
Improper
Access Control in the AMD SPI protection feature may allow a user with Ring0
(kernel mode) privileged access to bypass protections potentially resulting in
loss of integrity and availability.
Affected
144 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | amd_ryzen_3000_series_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_4000_series_desktop_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_4000_series_mobile_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_5000_series_desktop_processor_with_radeon_graphics | — | — |
| amd | amd_ryzen_5000_series_mobile_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_5000_series_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_6000_series_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_7000_series_desktop_processor | — | — |
| amd | amd_ryzen_7020_series_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_7035_series_mobile_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_7040_series_mobile_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_7040_series_mobile_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_7045_series_mobile_processors | — | — |
| amd | amd_ryzen_embedded_v2000 | — | — |
| amd | amd_ryzen_embedded_v3000 | — | — |
| amd | ryzen_3_3200u_firmware | < cezannepi-fp6_1.0.1.0 | cezannepi-fp6_1.0.1.0 |
| amd | ryzen_3_3250c_firmware | < cezannepi-fp6_1.0.1.0 | cezannepi-fp6_1.0.1.0 |
| amd | ryzen_3_3250u_firmware | < cezannepi-fp6_1.0.1.0 | cezannepi-fp6_1.0.1.0 |
| amd | ryzen_3_3300u_firmware | < cezannepi-fp6_1.0.1.0 | cezannepi-fp6_1.0.1.0 |
| amd | ryzen_3_3350u_firmware | < cezannepi-fp6_1.0.1.0 | cezannepi-fp6_1.0.1.0 |
| amd | ryzen_3_4300g_firmware | < comboam4v2pi_1.2.0.c | comboam4v2pi_1.2.0.c |
| amd | ryzen_3_4300ge_firmware | < comboam4v2pi_1.2.0.c | comboam4v2pi_1.2.0.c |
| amd | ryzen_3_4300u_firmware | < renoirpi-fp6_1.0.0.d | renoirpi-fp6_1.0.0.d |
| amd | ryzen_3_5125c_firmware | < cezannepi-fp6_1.0.1.0 | cezannepi-fp6_1.0.1.0 |
| amd | ryzen_3_5300g_firmware | < comboam4v2pi_1.2.0.c | comboam4v2pi_1.2.0.c |
CVSS provenance
nvdv3.16.0MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
hw: amd: SPI bypass
vendor_redhat·2024-02-13·CVSS 6.0
CVE-2023-20579 [MEDIUM] CWE-284 hw: amd: SPI bypass
hw: amd: SPI bypass
Improper
Access Control in the AMD SPI protection feature may allow a user with Ring0
(kernel mode) privileged access to bypass protections potentially resulting in
loss of integrity and availability.
A vulnerability was found in AMD hardware due to improper access control in the AMD SPI protection feature. This issue may allow a local user with Ring0 (kernel mode) privileged access to bypass protections, potentially resulting in loss of integrity and availability.
Statement: The PSP and AEGIS vulnerabilities necessitate a BIOS update, as they are not inherent to the CPU and cannot be addressed through CPU microcode updates. This requires a UEFI firmware update from the device vendor, distinct from updates in the linux-firmware package. Therefore, linux-firmware on R
GHSA
GHSA-263h-mwf7-v6rq: Improper
Access Control in the AMD SPI protection feature may allow a user with Ring0
(kernel mode) privileged access to bypass protections potentiall
ghsa_unreviewed·2024-02-13
CVE-2023-20579 [MEDIUM] CWE-284 GHSA-263h-mwf7-v6rq: Improper
Access Control in the AMD SPI protection feature may allow a user with Ring0
(kernel mode) privileged access to bypass protections potentiall
Improper
Access Control in the AMD SPI protection feature may allow a user with Ring0
(kernel mode) privileged access to bypass protections potentially resulting in
loss of integrity and availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-13
Published