Insufficient Data Authenticity Verification in AGESA by AMD
CVE-2023-20576
7.7HIGH
Key Information:
- Vendor
Amd
- Status
- Vendor
- CVE Published:
- 2 September 2026
What is CVE-2023-20576?
A security vulnerability in AMD's AGESA firmware exists due to insufficient verification of data authenticity. This flaw may allow attackers to exploit the system by updating the Serial Peripheral Interface (SPI) ROM data. Such unauthorized modifications can lead to critical impacts, including potential denial of service conditions and privilege escalation risks. Users are encouraged to apply the latest security updates as provided by AMD to mitigate these risks.
Affected Version(s)
AMD Ryzen™ 3000 Series Desktop Processors ComboAM4v2 1.2.0.B
AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics ComboAM4v2 1.2.0.B
AMD Ryzen™ 5000 Series Desktop Processors ComboAM4v2v 1.2.0.B