CVE-2023-20587Improper Access Control in AMD 1ST GEN AMD Epyc Processors

Severity
7.1HIGHNVD
EPSS
0.0%
top 89.82%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13

Description

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:NExploitability: 1.8 | Impact: 5.2

Affected Packages8 packages

CVEListV5amd/amd_epyc_embedded_3000various
CVEListV5amd/amd_epyc_embedded_7002various
CVEListV5amd/amd_epyc_embedded_7003various
CVEListV5amd/amd_epyc_embedded_9003various

🔴Vulnerability Details

2
CVEList
CVE-2023-20587: Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution2024-02-13
GHSA
GHSA-3jmf-c2v9-xc39: Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution2024-02-13

📋Vendor Advisories

1
Red Hat
hw: amd: failure to sanitize input in SMM2024-02-13
CVE-2023-20587 — Improper Access Control in AMD | cvebase