Improper Resource Isolation in AMD System-on-a-Chip Products
CVE-2023-31325

7.2HIGH

What is CVE-2023-31325?

The vulnerability arises from inadequate isolation of shared resources within AMD's System-on-a-Chip architecture. This flaw may allow a privileged attacker to manipulate the contents of the Platform Security Processor (PSP) reserved DRAM region. As a result, this manipulation poses significant risks to the confidentiality and integrity of sensitive data, potentially leading to unauthorized access and data compromise.

Affected Version(s)

AMD Radeon™ PRO W7000 Series Graphics Products AMD Software: PRO Edition 24.Q2 (24.10.20)

AMD Radeon™ RX 7000 Series Graphics Products AMD Software: Adrenalin Edition 24.7.1 (24.10.29.01)

AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics PhoenixPI-FP8-FP7_1.1.0.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2023-31325 : Improper Resource Isolation in AMD System-on-a-Chip Products