CVE-2023-20521
3.3LOW
Key Information:
- Vendor
- Amd
- Status
- Vendor
- CVE Published:
- 14 November 2023
Summary
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
Affected Version(s)
1st Gen AMD EPYC™ Processors x86 various
2nd Gen AMD EPYC™ Processors x86 various
3rd Gen AMD EPYC™ Processors x86 various
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database