6.5
CVE-2023-20575
- EPSS 0.33%
- Veröffentlicht 11.07.2023 19:15:09
- Zuletzt bearbeitet 27.11.2024 16:15:08
- Quelle psirt@amd.com
- Teams Watchlist Login
- Unerledigt Login
A potential power side-channel vulnerability in some AMD processors may allow an authenticated attacker to use the power reporting functionality to monitor a program’s execution inside an AMD SEV VM potentially resulting in a leak of sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Amd ≫ Epyc 7251 Firmware Version-
Amd ≫ Epyc 7281 Firmware Version-
Amd ≫ Epyc 7301 Firmware Version-
Amd ≫ Epyc 7351 Firmware Version-
Amd ≫ Epyc 7351p Firmware Version-
Amd ≫ Epyc 7401 Firmware Version-
Amd ≫ Epyc 7401p Firmware Version-
Amd ≫ Epyc 7451 Firmware Version-
Amd ≫ Epyc 7501 Firmware Version-
Amd ≫ Epyc 7551 Firmware Version-
Amd ≫ Epyc 7551p Firmware Version-
Amd ≫ Epyc 7601 Firmware Version-
Amd ≫ Epyc Embedded 3101 Firmware Version-
Amd ≫ Epyc Embedded 3151 Firmware Version-
Amd ≫ Epyc Embedded 3201 Firmware Version-
Amd ≫ Epyc Embedded 3251 Firmware Version-
Amd ≫ Epyc Embedded 3255 Firmware Version-
Amd ≫ Epyc Embedded 3451 Firmware Version-
Amd ≫ Epyc 7232p Firmware Version-
Amd ≫ Epyc 7252 Firmware Version-
Amd ≫ Epyc 7262 Firmware Version-
Amd ≫ Epyc 7272 Firmware Version-
Amd ≫ Epyc 7302 Firmware Version-
Amd ≫ Epyc 7302p Firmware Version-
Amd ≫ Epyc 7352 Firmware Version-
Amd ≫ Epyc 7402 Firmware Version-
Amd ≫ Epyc 7402p Firmware Version-
Amd ≫ Epyc 7452 Firmware Version-
Amd ≫ Epyc 7502 Firmware Version-
Amd ≫ Epyc 7502p Firmware Version-
Amd ≫ Epyc 7532 Firmware Version-
Amd ≫ Epyc 7542 Firmware Version-
Amd ≫ Epyc 5552 Firmware Version-
Amd ≫ Epyc 7642 Firmware Version-
Amd ≫ Epyc 7662 Firmware Version-
Amd ≫ Epyc 7702 Firmware Version-
Amd ≫ Epyc 7702p Firmware Version-
Amd ≫ Epyc 7742 Firmware Version-
Amd ≫ Epyc 7f32 Firmware Version-
Amd ≫ Epyc 7f52 Firmware Version-
Amd ≫ Epyc 7f72 Firmware Version-
Amd ≫ Epyc 72f3 Firmware Version-
Amd ≫ Epyc 7313 Firmware Version-
Amd ≫ Epyc 7313p Firmware Version-
Amd ≫ Epyc 7343 Firmware Version-
Amd ≫ Epyc 7373x Firmware Version-
Amd ≫ Epyc 73f3 Firmware Version-
Amd ≫ Epyc 7413 Firmware Version-
Amd ≫ Epyc 7443 Firmware Version-
Amd ≫ Epyc 7443p Firmware Version-
Amd ≫ Epyc 7453 Firmware Version-
Amd ≫ Epyc 7473x Firmware Version-
Amd ≫ Epyc 74f3 Firmware Version-
Amd ≫ Epyc 7513 Firmware Version-
Amd ≫ Epyc 7543 Firmware Version-
Amd ≫ Epyc 7543p Firmware Version-
Amd ≫ Epyc 7573x Firmware Version-
Amd ≫ Epyc 75f3 Firmware Version-
Amd ≫ Epyc 7643 Firmware Version-
Amd ≫ Epyc 7663 Firmware Version-
Amd ≫ Epyc 7713 Firmware Version-
Amd ≫ Epyc 7713p Firmware Version-
Amd ≫ Epyc 7763 Firmware Version-
Amd ≫ Epyc 7773x Firmware Version-
Amd ≫ Epyc 9124 Firmware Version-
Amd ≫ Epyc 9174f Firmware Version-
Amd ≫ Epyc 9184x Firmware Version-
Amd ≫ Epyc 9224 Firmware Version-
Amd ≫ Epyc 9254 Firmware Version-
Amd ≫ Epyc 9274f Firmware Version-
Amd ≫ Epyc 9334 Firmware Version-
Amd ≫ Epyc 9354 Firmware Version-
Amd ≫ Epyc 9354p Firmware Version-
Amd ≫ Epyc 9374f Firmware Version-
Amd ≫ Epyc 9384x Firmware Version-
Amd ≫ Epyc 9454 Firmware Version-
Amd ≫ Epyc 9454p Firmware Version-
Amd ≫ Epyc 9474f Firmware Version-
Amd ≫ Epyc 9534 Firmware Version-
Amd ≫ Epyc 9554p Firmware Version-
Amd ≫ Epyc 9554 Firmware Version-
Amd ≫ Epyc 9634 Firmware Version-
Amd ≫ Epyc 9654 Firmware Version-
Amd ≫ Epyc 9654p Firmware Version-
Amd ≫ Epyc 9684x Firmware Version-
Amd ≫ Epyc 9734 Firmware Version-
Amd ≫ Epyc 9754 Firmware Version-
Amd ≫ Epyc 9754s Firmware Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.33% | 0.555 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-203 Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.