5.7

CVE-2023-20521

TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AmdEpyc 7001 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7001 Version-
AmdEpyc 7251 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7251 Version-
AmdEpyc 7261 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7261 Version-
AmdEpyc 7281 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7281 Version-
AmdEpyc 7301 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7301 Version-
AmdEpyc 7351 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7351 Version-
AmdEpyc 7351p Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7351p Version-
AmdEpyc 7371 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7371 Version-
AmdEpyc 7401 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7401 Version-
AmdEpyc 7401p Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7401p Version-
AmdEpyc 7451 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7451 Version-
AmdEpyc 7501 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7501 Version-
AmdEpyc 7551 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7551 Version-
AmdEpyc 7551p Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7551p Version-
AmdEpyc 7601 Firmware Version < naplespi_1.0.0.h
   AmdEpyc 7601 Version-
AmdEpyc 7232p Firmware Version < romepi_1.0.0.d
   AmdEpyc 7232p Version-
AmdEpyc 7252 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7252 Version-
AmdEpyc 7262 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7262 Version-
AmdEpyc 7272 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7272 Version-
AmdEpyc 7282 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7282 Version-
AmdEpyc 7302 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7302 Version-
AmdEpyc 7302p Firmware Version < romepi_1.0.0.d
   AmdEpyc 7302p Version-
AmdEpyc 7352 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7352 Version-
AmdEpyc 7402 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7402 Version-
AmdEpyc 7402p Firmware Version < romepi_1.0.0.d
   AmdEpyc 7402p Version-
AmdEpyc 7452 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7452 Version-
AmdEpyc 7502 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7502 Version-
AmdEpyc 7502p Firmware Version < romepi_1.0.0.d
   AmdEpyc 7502p Version-
AmdEpyc 7532 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7532 Version-
AmdEpyc 7542 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7542 Version-
AmdEpyc 7552 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7552 Version-
AmdEpyc 7642 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7642 Version-
AmdEpyc 7662 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7662 Version-
AmdEpyc 7702 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7702 Version-
AmdEpyc 7702p Firmware Version < romepi_1.0.0.d
   AmdEpyc 7702p Version-
AmdEpyc 7742 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7742 Version-
AmdEpyc 7f32 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7f32 Version-
AmdEpyc 7f52 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7f52 Version-
AmdEpyc 7f72 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7f72 Version-
AmdEpyc 7h12 Firmware Version < romepi_1.0.0.d
   AmdEpyc 7h12 Version-
AmdEpyc 7763 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7763 Version-
AmdEpyc 7713p Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7713p Version-
AmdEpyc 7713 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7713 Version-
AmdEpyc 7663p Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7663p Version-
AmdEpyc 7663 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7663 Version-
AmdEpyc 7643p Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7643p Version-
AmdEpyc 7773x Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7773x Version-
AmdEpyc 7643 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7643 Version-
AmdEpyc 7573x Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7573x Version-
AmdEpyc 75f3 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 75f3 Version-
AmdEpyc 7543p Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7543p Version-
AmdEpyc 7543 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7543 Version-
AmdEpyc 7513 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7513 Version-
AmdEpyc 7473x Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7473x Version-
AmdEpyc 7453 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7453 Version-
AmdEpyc 74f3 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 74f3 Version-
AmdEpyc 7443p Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7443p Version-
AmdEpyc 7443 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7443 Version-
AmdEpyc 7413 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7413 Version-
AmdEpyc 7373x Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7373x Version-
AmdEpyc 73f3 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 73f3 Version-
AmdEpyc 7343 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7343 Version-
AmdEpyc 7313p Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7313p Version-
AmdEpyc 7313 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7313 Version-
AmdEpyc 7303p Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7303p Version-
AmdEpyc 7303 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7303 Version-
AmdEpyc 72f3 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 72f3 Version-
AmdEpyc 7203p Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7203p Version-
AmdEpyc 7203 Firmware Version < milanpi_1.0.0.7
   AmdEpyc 7203 Version-
AmdAthlon Pro 300ge Firmware Version-
   AmdAthlon Pro 300ge Version-
AmdAthlon Gold 3150g Firmware Version-
   AmdAthlon Gold 3150g Version-
AmdRyzen Threadripper 2990wx Firmware Version < summitpi-sp3r2_1.1.0.6
   AmdRyzen Threadripper 2990wx Version-
AmdRyzen Threadripper 2970wx Firmware Version < summitpi-sp3r2_1.1.0.6
   AmdRyzen Threadripper 2970wx Version-
AmdRyzen Threadripper 2950x Firmware Version < summitpi-sp3r2_1.1.0.6
   AmdRyzen Threadripper 2950x Version-
AmdRyzen Threadripper 2920x Firmware Version < summitpi-sp3r2_1.1.0.6
   AmdRyzen Threadripper 2920x Version-
AmdRyzen 7 3780u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 7 3780u Version-
AmdRyzen 7 3750h Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 7 3750h Version-
AmdRyzen 7 3700c Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 7 3700c Version-
AmdRyzen 7 3700u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 7 3700u Version-
AmdRyzen 5 3580u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 5 3580u Version-
AmdRyzen 5 3550h Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 5 3550h Version-
AmdRyzen 5 3500c Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 5 3500c Version-
AmdRyzen 5 3500u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 5 3500u Version-
AmdRyzen 5 3450u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 5 3450u Version-
AmdRyzen 3 3350u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 3 3350u Version-
AmdRyzen 3 3300u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 3 3300u Version-
AmdRyzen 3 3250u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 3 3250u Version-
AmdRyzen 3 3250c Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 3 3250c Version-
AmdRyzen 3 3200u Firmware Version < picassopi-fp5_1.0.0.e
   AmdRyzen 3 3200u Version-
AmdAmd 3015e Firmware Version < pollockpi-ft5_1.0.0.4
   AmdAmd 3015e Version-
AmdAmd 3015ce Firmware Version < pollockpi-ft5_1.0.0.4
   AmdAmd 3015ce Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.04% 0.079
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.7 0.5 5.2
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
psirt@amd.com 3.3 0.3 2.7
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.