Memory Integrity Vulnerability in AMD Products Due to SMM Configuration Flaw
CVE-2022-23830

1.9LOW

Key Information:

Summary

A configuration issue in the System Management Mode (SMM) can lead to a situation where desired immutability is not maintained when Secure Nested Paging (SNP) is active. This flaw may expose the system to potential risks associated with the integrity of guest memory, impacting overall security.

Affected Version(s)

3rd Gen AMD EPYC™ Processors x86 various

4th Gen AMD EPY™ Processors x86 various

AMD EPYC™ Embedded 7003 various

References

CVSS V3.1

Score:
1.9
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.