CVE-2023-31315
published 2024-08-12CVE-2023-31315: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled…
PriorityP338high7.5CVSS 3.1
AVLACHPRHUINSCCHIHAH
EPSS
0.62%
45.8th percentile
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
Affected
22 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 1st_gen_amd_epyc_processors | >= various < Naples PI 1.0.0.M | Naples PI 1.0.0.M |
| amd | 2nd_gen_amd_epyc_processors | >= various < Rome PI 1.0.0.J | Rome PI 1.0.0.J |
| amd | 3rd_gen_amd_epyc_processors | >= various < Milan PI 1.0.0.D | Milan PI 1.0.0.D |
| amd | amd_epyc_embedded_3000 | — | — |
| amd | amd_epyc_embedded_7002 | — | — |
| amd | amd_epyc_embedded_7003 | — | — |
| amd | amd_ryzen_3000_series_desktop_processors | — | — |
| amd | amd_ryzen_3000_series_mobile_processor_with_radeon_graphics | >= various < Picasso-FP5 1.0.1.2 | Picasso-FP5 1.0.1.2 |
| amd | amd_ryzen_4000_series_desktop_processors_with_radeon_graphics | >= various < ComboAM4v2PI 1.2.0.cb | ComboAM4v2PI 1.2.0.cb |
| amd | amd_ryzen_7000_series_desktop_processors | >= various < ComboAM5PI 1.2.0.1 | ComboAM5PI 1.2.0.1 |
| amd | amd_ryzen_7020_series_processors_with_radeon_graphics | >= various < MendocinoPI-FT6 1.0.0.7 | MendocinoPI-FT6 1.0.0.7 |
| amd | amd_ryzen_7030_series_mobile_processors_with_radeon_graphics | >= various < CezannePI-FP6 | CezannePI-FP6 |
| amd | amd_ryzen_embedded_5000 | — | — |
| amd | amd_ryzen_embedded_7000 | — | — |
| amd | amd_ryzen_embedded_r1000 | — | — |
| amd | amd_ryzen_embedded_r2000 | — | — |
| amd | amd_ryzen_embedded_v1000 | — | — |
| amd | amd_ryzen_embedded_v2000 | — | — |
| amd | amd_ryzen_embedded_v3000 | — | — |
| amd | amd_ryzen_threadripper_3000_series_processors | >= various < CastlePeakPI-SP3r3 1.0.0.B | CastlePeakPI-SP3r3 1.0.0.B |
| amd | amd_ryzen_threadripper_pro_processors | >= various < ChagallWSPI-sWRX8 1.0.0.8 | ChagallWSPI-sWRX8 1.0.0.8 |
| debian | amd64-microcode | < amd64-microcode 3.20240710.2~deb12u1 (bookworm) | amd64-microcode 3.20240710.2~deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SCALANCE W700
cisa_ics·2025-02-13
Siemens SCALANCE W700
ICS Advisory
##
Siemens SCALANCE W700
Release DateFebruary 13, 2025
Alert CodeICSA-25-044-09
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE W700
- Vulnerabilities: Double Free, Improper Restriction of Communication Channel to Intended Endpoints, Improper Resource Sh
Ubuntu
AMD Microcode vulnerability
vendor_ubuntu·2024-10-21
CVE-2023-31315 AMD Microcode vulnerability
Title: AMD Microcode vulnerability
Summary: AMD processors may allow a privileged local attacker to further escalate their
privileged and execute arbitrary code within the processor's firmware layer.
Enrique Nissim and Krzysztof Okupski discovered that some AMD processors
did not properly restrict access to the System Management Mode (SMM)
configuration when the SMM Lock was enabled. A privileged local attacker
could possibly use this issue to further escalate their privileges and
execute arbitrary code within the processor's firmware layer.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
Red Hat
hw: amd: SMM Lock Bypass
vendor_redhat·2024-08-09·CVSS 7.5
CVE-2023-31315 [HIGH] hw: amd: SMM Lock Bypass
hw: amd: SMM Lock Bypass
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
A flaw was found in hw. Improper validation in a model-specific register (MSR) could allow a malicious program with ring0 access to modify the SMM configuration while the SMI lock is enabled. This issue can lead to arbitrary code execution.
Statement: The CVE-2023-31315 vulnerability, known as "AMD Sinkclose," is a important security issue due to its ability to allow privilege escalation from ring 0 to ring -2, the most privileged execution mode on a CPU. This bypasses System Management Mode (SMM) protections, enabling attackers to execute arbitrary code wi
Debian
CVE-2023-31315: amd64-microcode - Improper validation in a model specific register (MSR) could allow a malicious p...
vendor_debian·2023·CVSS 7.5
CVE-2023-31315 [HIGH] CVE-2023-31315: amd64-microcode - Improper validation in a model specific register (MSR) could allow a malicious p...
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
Scope: local
bookworm: resolved (fixed in 3.20240710.2~deb12u1)
bullseye: resolved (fixed in 3.20240710.2~deb11u1)
forky: resolved (fixed in 3.20240710.1)
sid: resolved (fixed in 3.20240710.1)
trixie: resolved (fixed in 3.20240710.1)
OSV
CVE-2023-31315: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is
osv·2024-08-12·CVSS 7.5
CVE-2023-31315 [HIGH] CVE-2023-31315: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
GHSA
GHSA-7r5c-r5ww-995h: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is
ghsa_unreviewed·2024-08-12
CVE-2023-31315 [HIGH] CWE-94 GHSA-7r5c-r5ww-995h: Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
No detection rules found.
No public exploits indexed.
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.htmlhttps://media.defcon.org/DEF%20CON%2032/DEF%20CON%2032%20presentations/DEF%20CON%2032%20-%20Enrique%20Nissim%20Krzysztof%20Okupski%20-%20AMD%20Sinkclose%20Universal%20Ring-2%20Privilege%20Escalation.pdfhttps://news.ycombinator.com/item?id=41475975https://www.darkreading.com/remote-workforce/amd-issues-updates-for-silicon-level-sinkclose-flaw
2024-08-12
Published