7.8

CVE-2023-20548

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amd ≫ Rocm Version < 6.2.0
   Amd ≫ Instinct Mi210 Version -
   Amd ≫ Instinct Mi250 Version -
   Amd ≫ Instinct Mi300a Version -
   Amd ≫ Instinct Mi300x Version -
Amd ≫ Radeon Software SwEdition pro Version < 25.q2
   Amd ≫ Radeon Pro W5500 Version -
   Amd ≫ Radeon Pro W5500x Version -
   Amd ≫ Radeon Pro W5700 Version -
   Amd ≫ Radeon Pro W5700x Version -
Amd ≫ Radeon Software SwEdition adrenalin Version < 24.6.1
   Amd ≫ Radeon Rx 5300 Version -
   Amd ≫ Radeon Rx 5300 Xt Version -
   Amd ≫ Radeon Rx 5300m Version -
   Amd ≫ Radeon Rx 5500 Version -
   Amd ≫ Radeon Rx 5500 Xt Version -
   Amd ≫ Radeon Rx 5500m Version -
   Amd ≫ Radeon Rx 5600 Version -
   Amd ≫ Radeon Rx 5600 Xt Version -
   Amd ≫ Radeon Rx 5600m Version -
   Amd ≫ Radeon Rx 5700 Version -
   Amd ≫ Radeon Rx 5700 Xt Version -
   Amd ≫ Radeon Rx 5700m Version -
Amd ≫ Radeon Vii Firmware Version -
   Amd ≫ Radeon Vii Version -
Amd ≫ Radeon Pro Vii Firmware Version -
   Amd ≫ Radeon Pro Vii Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.1% 0.011
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
AMD 7.1 0 0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check.

https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6024.html
Vendor Advisory