Improper Access Control in IOMMU Affects AMD Products
CVE-2023-20581

2.5LOW

What is CVE-2023-20581?

The vulnerability arises from inadequate access control mechanisms in the IOMMU, enabling a privileged attacker to circumvent the Rapid Memory Protection (RMP) checks. This could lead to significant risks concerning the integrity of guest memory, potentially allowing unauthorized access or manipulation of memory spaces within virtualized environments. It is crucial for affected users to refer to AMD's security bulletins for guidance on mitigation and remediation strategies.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

AMD EPYC™ 9004 Processors GenoaPI 1.0.0.C

AMD EPYC™ Embedded 9004 EmbGenoaPI-SP5 1.0.0.7

AMD EPYC™ 9004 Processors GenoaPI 1.0.0.C

References

CVSS V3.1

Score:
2.5
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.