Weak Initialization Vector Generations May Lead to Information Disclosure
CVE-2023-31305
1.9LOW
Key Information:
- Vendor
Amd
- Vendor
- CVE Published:
- 13 August 2024
What is CVE-2023-31305?
The Power Management Firmware developed by AMD is affected by a vulnerability related to the generation of weak and predictable Initialization Vector (IV). An attacker with the necessary privileges can exploit this weakness by reusing IV values, enabling them to potentially reverse-engineer sensitive debug data. This could lead to unauthorized access to confidential information and pose a significant threat to system integrity.
Affected Version(s)
AMD Radeon™ PRO W6000 Series Graphics Cards AMD Software: PRO Edition 23.Q4 (23.30.13.03)
AMD Radeon™ RX 6000 Series Graphics Cards AMD Software: Adrenalin Edition 23.12.1 (23.30.13.01)