Insufficient Data Authenticity Verification in AGESA by AMD
CVE-2023-20576

7.7HIGH

What is CVE-2023-20576?

A security vulnerability in AMD's AGESA firmware exists due to insufficient verification of data authenticity. This flaw may allow attackers to exploit the system by updating the Serial Peripheral Interface (SPI) ROM data. Such unauthorized modifications can lead to critical impacts, including potential denial of service conditions and privilege escalation risks. Users are encouraged to apply the latest security updates as provided by AMD to mitigate these risks.

Affected Version(s)

AMD Ryzen™ 3000 Series Desktop Processors ComboAM4v2 1.2.0.B

AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics ComboAM4v2 1.2.0.B

AMD Ryzen™ 5000 Series Desktop Processors ComboAM4v2v 1.2.0.B

References

CVSS V3.1

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.