Improper Input Validation in AMD ASP Bootloader Vulnerability
CVE-2023-20527

6.5MEDIUM

Key Information:

Vendor
AMD
Vendor
CVE Published:
11 January 2023

Summary

A vulnerability exists in the AMD ASP Bootloader due to improper validation of syscall inputs. This flaw can be exploited by privileged attackers, allowing them to read memory out-of-bounds. Such exploitation may potentially lead to a denial-of-service condition, affecting the stability and security of systems utilizing this bootloader. It is crucial for users and administrators to apply the necessary patches and monitor for any unusual activity to mitigate associated risks.

Affected Version(s)

1st Gen EPYC x86 various

2nd Gen EPYC x86 various

3rd Gen EPYC x86 various

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.