8.8

CVE-2023-20559



Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.



Data is provided by the National Vulnerability Database (NVD)
AmdRyzen 7 5700g Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 7 5700g Version-
AmdRyzen 7 5700ge Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 7 5700ge Version-
AmdRyzen 5 5600g Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 5 5600g Version-
AmdRyzen 5 5600ge Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 5 5600ge Version-
AmdRyzen 3 5300g Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 3 5300g Version-
AmdRyzen 3 5300ge Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 3 5300ge Version-
AmdRyzen 9 5980hx Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 9 5980hx Version-
AmdRyzen 9 5980hs Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 9 5980hs Version-
AmdRyzen 7 5825u Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 7 5825u Version-
AmdRyzen 9 5900hx Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 9 5900hx Version-
AmdRyzen 9 5900hs Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 9 5900hs Version-
AmdRyzen 7 5825c Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 7 5825c Version-
AmdRyzen 7 5800h Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 7 5800h Version-
AmdRyzen 5 5625u Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 5 5625u Version-
AmdRyzen 7 5800hs Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 7 5800hs Version-
AmdRyzen 5 5625c Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 5 5625c Version-
AmdRyzen 5 5600h Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 5 5600h Version-
AmdRyzen 5 5600hs Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 5 5600hs Version-
AmdRyzen 7 5800u Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 7 5800u Version-
AmdRyzen 5 5600u Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 5 5600u Version-
AmdRyzen 5 5560u Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 5 5560u Version-
AmdRyzen 3 5425u Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 3 5425u Version-
AmdRyzen 3 5425c Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 3 5425c Version-
AmdRyzen 3 5400u Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 3 5400u Version-
AmdRyzen 3 5125c Firmware Version < cezannepi-fp6_1.0.0.9
   AmdRyzen 3 5125c Version-
AmdAthlon Silver 3050u Firmware Version-
   AmdAthlon Silver 3050u Version-
AmdAthlon Gold 3150u Firmware Version-
   AmdAthlon Gold 3150u Version-
AmdRyzen 3 3200u Firmware Version-
   AmdRyzen 3 3200u Version-
AmdRyzen 3 3250u Firmware Version-
   AmdRyzen 3 3250u Version-
AmdRyzen 3 3300u Firmware Version-
   AmdRyzen 3 3300u Version-
AmdRyzen 3 3350u Firmware Version-
   AmdRyzen 3 3350u Version-
AmdRyzen 3 3450u Firmware Version-
   AmdRyzen 3 3450u Version-
AmdRyzen 3 3500u Firmware Version-
   AmdRyzen 3 3500u Version-
AmdRyzen 3 3500c Firmware Version-
   AmdRyzen 3 3500c Version-
AmdRyzen 3 3550h Firmware Version-
   AmdRyzen 3 3550h Version-
AmdRyzen 3 3580u Firmware Version-
   AmdRyzen 3 3580u Version-
AmdRyzen 3 3700u Firmware Version-
   AmdRyzen 3 3700u Version-
AmdRyzen 3 3700c Firmware Version-
   AmdRyzen 3 3700c Version-
AmdRyzen 3 3750h Firmware Version-
   AmdRyzen 3 3750h Version-
AmdRyzen 3 3780u Firmware Version-
   AmdRyzen 3 3780u Version-
AmdRyzen 3 2200u Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 3 2200u Version-
AmdRyzen 3 2300u Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 3 2300u Version-
AmdRyzen 5 2500u Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 5 2500u Version-
AmdRyzen 5 2600 Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 5 2600 Version-
AmdRyzen 5 2600h Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 5 2600h Version-
AmdRyzen 5 2600x Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 5 2600x Version-
AmdRyzen 5 2700 Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 5 2700 Version-
AmdRyzen 5 2700x Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 5 2700x Version-
AmdRyzen 7 2700 Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 7 2700 Version-
AmdRyzen 7 2700u Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 7 2700u Version-
AmdRyzen 7 2700x Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 7 2700x Version-
AmdRyzen 7 2800h Firmware Version < comboam4v2_pi_1.2.0.6c
   AmdRyzen 7 2800h Version-
AmdRyzen 3 3300x Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 3 3300x Version-
AmdRyzen 5 3500 Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 5 3500 Version-
AmdRyzen 5 3500x Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 5 3500x Version-
AmdRyzen 5 3600 Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 5 3600 Version-
AmdRyzen 5 3600x Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 5 3600x Version-
AmdRyzen 5 3600xt Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 5 3600xt Version-
AmdRyzen 7 3700x Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 7 3700x Version-
AmdRyzen 7 3800x Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 7 3800x Version-
AmdRyzen 7 3800xt Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 7 3800xt Version-
AmdRyzen 9 3900 Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 9 3900 Version-
AmdRyzen 9 3900x Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 9 3900x Version-
AmdRyzen 9 3900xt Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 9 3900xt Version-
AmdRyzen 9 3950x Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 9 3950x Version-
AmdRyzen 9 Pro 3900 Firmware Version < comboam4_v2_pi_1.2.0.6c
   AmdRyzen 9 Pro 3900 Version-
AmdRyzen Threadripper 2990wx Firmware Version < summitpi-sp3r2_1.1.0.5
   AmdRyzen Threadripper 2990wx Version-
AmdRyzen Threadripper 2970wx Firmware Version < summitpi-sp3r2_1.1.0.5
   AmdRyzen Threadripper 2970wx Version-
AmdRyzen Threadripper 2950x Firmware Version < summitpi-sp3r2_1.1.0.5
   AmdRyzen Threadripper 2950x Version-
AmdRyzen Threadripper 2920x Firmware Version < summitpi-sp3r2_1.1.0.5
   AmdRyzen Threadripper 2920x Version-
AmdRyzen Threadripper 3990x Firmware Version < castlepeakpi-sp3r3_1.0.0.6
   AmdRyzen Threadripper 3990x Version-
AmdRyzen Threadripper 3970x Firmware Version < castlepeakpi-sp3r3_1.0.0.6
   AmdRyzen Threadripper 3970x Version-
AmdRyzen Threadripper 3960x Firmware Version < castlepeakpi-sp3r3_1.0.0.6
   AmdRyzen Threadripper 3960x Version-
AmdRyzen Threadripper Pro 3795wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 3945wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 3955wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 3975wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 3995wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 5945wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 5955wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 5965wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 5975wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen Threadripper Pro 5995wx Firmware Version < castlepeakwspi-swrx8_1.0.0.9
AmdRyzen 7 4700g Firmware Version < renoirpi-fp6_1.0.0.7
   AmdRyzen 7 4700g Version-
AmdRyzen 7 4700ge Firmware Version < renoirpi-fp6_1.0.0.7
   AmdRyzen 7 4700ge Version-
AmdRyzen 5 4600g Firmware Version < renoirpi-fp6_1.0.0.7
   AmdRyzen 5 4600g Version-
AmdRyzen 5 4600ge Firmware Version < renoirpi-fp6_1.0.0.7
   AmdRyzen 5 4600ge Version-
AmdRyzen 3 4300g Firmware Version < renoirpi-fp6_1.0.0.7
   AmdRyzen 3 4300g Version-
AmdRyzen 3 4300ge Firmware Version < renoirpi-fp6_1.0.0.7
   AmdRyzen 3 4300ge Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.26% 0.459
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-691 Insufficient Control Flow Management

The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.