7.8

CVE-2023-20548

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AmdRocm Version < 6.2.0
   AmdInstinct Mi210 Version-
   AmdInstinct Mi250 Version-
   AmdInstinct Mi300a Version-
   AmdInstinct Mi300x Version-
AmdRadeon Software SwEditionpro Version < 25.q2
   AmdRadeon Pro W5500 Version-
   AmdRadeon Pro W5500x Version-
   AmdRadeon Pro W5700 Version-
   AmdRadeon Pro W5700x Version-
AmdRadeon Software SwEditionadrenalin Version < 24.6.1
   AmdRadeon Rx 5300 Version-
   AmdRadeon Rx 5300 Xt Version-
   AmdRadeon Rx 5300m Version-
   AmdRadeon Rx 5500 Version-
   AmdRadeon Rx 5500 Xt Version-
   AmdRadeon Rx 5500m Version-
   AmdRadeon Rx 5600 Version-
   AmdRadeon Rx 5600 Xt Version-
   AmdRadeon Rx 5600m Version-
   AmdRadeon Rx 5700 Version-
   AmdRadeon Rx 5700 Xt Version-
   AmdRadeon Rx 5700m Version-
AmdRadeon Vii Firmware Version-
   AmdRadeon Vii Version-
AmdRadeon Pro Vii Firmware Version-
   AmdRadeon Pro Vii Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.006
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.1 6
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
psirt@amd.com 7.1 0 0
CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.