CVE-2023-20521
CVE-2023-20521
Vexday Risk Score
8Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 3.3EPSS 0.3%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Ciclo de vida
14 nov 2023Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L
Produtos afetados
AMD · 1st Gen AMD EPYC™ ProcessorsAMD · 2nd Gen AMD EPYC™ ProcessorsAMD · 3rd Gen AMD EPYC™ ProcessorsAMD · AMD EPYC™ Embedded 3000AMD · AMD EPYC™ Embedded 7002AMD · AMD EPYC™ Embedded 7003AMD · AMD Ryzen™ Embedded R1000AMD · AMD Ryzen™ Embedded R2000AMD · AMD Ryzen™ Embedded V1000AMD · Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics “Picasso” AM4AMD · Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Dali”/”Dali” FP5AMD · Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Pollock”AMD · Ryzen™ 3000 Series Mobile Processor with Radeon™ Graphics “Picasso” FP5AMD · Ryzen™ Threadripper™ 2000 Series Processors “Colfax”Quer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →