5.7

CVE-2023-20515

Improper access control in the fTPM driver in the trusted OS could allow a privileged attacker to corrupt system memory, potentially leading to loss of integrity, confidentiality, or availability.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerAMD
Produkt AMD Ryzen™ 3000 Series Desktop Processors
Default Statusaffected
Version ComboAM4v2PI 1.2.0.CA
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 5000 Series Desktop Processors
Default Statusaffected
Version ComboAM4v2PI 1.2.0.CA
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics
Default Statusaffected
Version ComboAM4v2PI 1.2.0.CA
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 7000 Series Desktop Processors
Default Statusaffected
Version ComboAM5 1.0.8.0
Status unaffected
HerstellerAMD
Produkt AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics
Default Statusaffected
Version ComboAM4v2PI 1.2.0.CA
Status unaffected
Version ComboAM4PI 1.0.0.B
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 4000 Series Desktop Processor with Radeon™ Graphics
Default Statusaffected
Version ComboAM4v2PI 1.2.0.CA
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 8000 Series Processor with Radeon™ Graphics
Default Statusaffected
Version ComboAM5 1.0.8.0
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Threadripper™ 3000 Series Processors
Default Statusaffected
Version CastlePeakPI-SP3r3 1.0.0.C
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors
Default Statusaffected
Version CastlePeakWSPI-sWRX8 1.0.0.E
Status unaffected
Version ChagallWSPI-sWRX8 1.0.0.9
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Threadripper™ PRO 5000WX- Series Desktop Processors
Default Statusaffected
Version ChagallWSPI-sWRX8 1.0.0.7
Status unaffected
HerstellerAMD
Produkt AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics
Default Statusaffected
Version Pollock-FT5 1.0.0.7
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ Graphics
Default Statusaffected
Version Picasso-FP5 1.0.1.1
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics
Default Statusaffected
Version RenoirPI-FP6 1.0.0.D
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics
Default Statusaffected
Version Cezanne-FP6 1.0.1.0
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics
Default Statusaffected
Version MendocinoPI-FT6 1.0.0.6
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 6000 Series Processor with Radeon™ Graphics
Default Statusaffected
Version RembrandtPI-FP7 1.0.0.9b
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 7035 Series Processor with Radeon™ Graphics
Default Statusaffected
Version RembrandtPI-FP7 1.0.0.9b
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 7040 Series Processors with Radeon™ Graphics
Default Statusaffected
Version PhoenixPI-FP8-FP7 1.0.8.0
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ 7000 Series Mobile Processors
Default Statusaffected
Version DragonRangeFL1PI 1.0.0.3b
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Embedded R1000
Default Statusaffected
Version EmbeddedPI-FP5 1.2.0.C
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Embedded R2000
Default Statusaffected
Version EmbeddedR2KPI-FP5 1.0.0.3
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Embedded 5000
Default Statusaffected
Version EmbAM4PI 1.0.0.5
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Embedded 7000
Default Statusaffected
Version EmbeddedAM5PI 1.0.0.0
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Embedded V2000
Default Statusaffected
Version EmbeddedPI-FP6 1.0.0.9
Status unaffected
HerstellerAMD
Produkt AMD Ryzen™ Embedded V1000
Default Statusaffected
Version No Fix Planned
Status affected
HerstellerAMD
Produkt AMD Ryzen™ Embedded V3000
Default Statusaffected
Version Embedded-PIFP7r2 1.0.0.8
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.097
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
psirt@amd.com 5.7 1.5 3.7
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:L/I:L/A:L
CWE-1284 Improper Validation of Specified Quantity in Input

The product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.