CVE-2023-20587
published 2024-02-13CVE-2023-20587: Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.
PriorityP335high7.1CVSS 3.1
AVLACLPRLUINSUCHIHAN
EPSS
0.17%
6.9th percentile
Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 1st_gen_amd_epyc_processors | — | — |
| amd | 2nd_gen_amd_epyc_processors | — | — |
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | 4th_gen_amd_epyc_processors | — | — |
| amd | amd_epyc_embedded_3000 | — | — |
| amd | amd_epyc_embedded_7002 | — | — |
| amd | amd_epyc_embedded_7003 | — | — |
| amd | amd_epyc_embedded_9003 | — | — |
CVSS provenance
nvdv3.17.1HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
vendor_redhat7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-3jmf-c2v9-xc39: Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution
ghsa_unreviewed·2024-02-13
CVE-2023-20587 [HIGH] CWE-284 GHSA-3jmf-c2v9-xc39: Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution
Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution.
Red Hat
hw: amd: failure to sanitize input in SMM
vendor_redhat·2024-02-13·CVSS 7.1
CVE-2023-20587 [HIGH] CWE-284 hw: amd: failure to sanitize input in SMM
hw: amd: failure to sanitize input in SMM
Improper
Access Control in System Management Mode (SMM) may allow an attacker access to
the SPI flash potentially leading to arbitrary code execution.
A vulnerability was found in AMD hardware due to improper access control in System Management Mode (SMM). This issue could allow a local unauthenticated attacker to execute arbitrary code.
Statement: The PSP and AEGIS vulnerabilities necessitate a BIOS update, as they are not inherent to the CPU and cannot be addressed through CPU microcode updates. This requires a UEFI firmware update from the device vendor, distinct from updates in the linux-firmware package. Therefore, linux-firmware on Red Hat Enterprise Linux is marked as not affected.
Mitigation: Mitigation for this issue is either not avai
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-13
Published