CVE-2023-20589
fTPM Voltage Fault Injection
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 0.5%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
08 Aug 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution.
Affected products
Ryzen™ PRO 5000 Series Desktop ProcessorsAMD · Athlon™ 3000 Series Mobile Processors with Radeon™ GraphicsAMD · Athlon™ 3000 Series Processors with Radeon™ GraphicsAMD · Athlon™ PRO 3000 Series Processors with Radeon™ Vega GraphicsAMD · Ryzen™ 3000 Series Desktop ProcessorsAMD · Ryzen™ 3000 Series Desktop Processors with Radeon™ GraphicsAMD · Ryzen™ 4000 Series Desktop Processors with Radeon™ GraphicsAMD · Ryzen™ 5000 Series Desktop ProcessorsAMD · Ryzen™ 5000 Series Desktop Processors with Radeon™ GraphicsAMD · Ryzen™ 5000 Series Processors with Radeon™ GraphicsAMD · Ryzen™ 6000 Series Processors with Radeon™ GraphicsAMD · Ryzen™ 7020 Series Processors with Radeon™ GraphicsAMD · Ryzen™ 7030 Series Processors with Radeon™ GraphicsAMD · Ryzen™ 7035 Series Processors with Radeon™ GraphicsAMD · Ryzen™ PRO 3000 Series Desktop ProcessorsAMD · Ryzen™ PRO 3000 Series Processors with Radeon™ Vega GraphicsAMD · Ryzen™ PRO 4000 Series Desktop ProcessorsAMD · Ryzen™ PRO 5000 Series ProcessorsAMD · Ryzen™ PRO 6000 Series ProcessorsAMD · Ryzen™ PRO 7030 Series ProcessorsAMD · Ryzen™ Threadripper™ 2000 Series ProcessorsAMD · Ryzen™ Threadripper™ 3000 Series ProcessorsAMD · Ryzen™ Threadripper™ 5000 Series ProcessorsWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →