Improper Input Validation in AMD ASP Bootloader Vulnerability
CVE-2023-20527
6.5MEDIUM
Key Information:
- Vendor
- AMD
- Vendor
- CVE Published:
- 11 January 2023
Summary
A vulnerability exists in the AMD ASP Bootloader due to improper validation of syscall inputs. This flaw can be exploited by privileged attackers, allowing them to read memory out-of-bounds. Such exploitation may potentially lead to a denial-of-service condition, affecting the stability and security of systems utilizing this bootloader. It is crucial for users and administrators to apply the necessary patches and monitor for any unusual activity to mitigate associated risks.
Affected Version(s)
1st Gen EPYC x86 various
2nd Gen EPYC x86 various
3rd Gen EPYC x86 various
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved