7.5

CVE-2023-20578

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow
an attacker with ring0 privileges and access to the
BIOS menu or UEFI shell to modify the communications buffer potentially
resulting in arbitrary code execution.

Data is provided by the National Vulnerability Database (NVD)
AmdEpyc 8024pn Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8024pn Version-
AmdEpyc 8024p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8024p Version-
AmdEpyc 8124pn Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8124pn Version-
AmdEpyc 8124p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8124p Version-
AmdEpyc 8224pn Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8224pn Version-
AmdEpyc 8224p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8224p Version-
AmdEpyc 8324pn Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8324pn Version-
AmdEpyc 8324p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8324p Version-
AmdEpyc 8434pn Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8434pn Version-
AmdEpyc 8434p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8434p Version-
AmdEpyc 8534pn Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8534pn Version-
AmdEpyc 8534p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 8534p Version-
AmdEpyc 9734 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9734 Version-
AmdEpyc 9754s Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9754s Version-
AmdEpyc 9754 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9754 Version-
AmdEpyc 9184x Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9184x Version-
AmdEpyc 9384x Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9384x Version-
AmdEpyc 9684x Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9684x Version-
AmdEpyc 9124 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9124 Version-
AmdEpyc 9174f Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9174f Version-
AmdEpyc 9224 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9224 Version-
AmdEpyc 9254 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9254 Version-
AmdEpyc 9274f Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9274f Version-
AmdEpyc 9334 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9334 Version-
AmdEpyc 9354 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9354 Version-
AmdEpyc 9354p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9354p Version-
AmdEpyc 9374f Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9374f Version-
AmdEpyc 9454 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9454 Version-
AmdEpyc 9454p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9454p Version-
AmdEpyc 9474f Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9474f Version-
AmdEpyc 9534 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9534 Version-
AmdEpyc 9554 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9554 Version-
AmdEpyc 9554p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9554p Version-
AmdEpyc 9634 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9634 Version-
AmdEpyc 9654 Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9654 Version-
AmdEpyc 9654p Firmware Version < genoapi_1.0.0.2
   AmdEpyc 9654p Version-
AmdEpyc 7203 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7203 Version-
AmdEpyc 7203p Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7203p Version-
AmdEpyc 72f3 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 72f3 Version-
AmdEpyc 7303 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7303 Version-
AmdEpyc 7303p Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7303p Version-
AmdEpyc 7313 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7313 Version-
AmdEpyc 7313p Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7313p Version-
AmdEpyc 7343 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7343 Version-
AmdEpyc 73f3 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 73f3 Version-
AmdEpyc 7373x Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7373x Version-
AmdEpyc 7413 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7413 Version-
AmdEpyc 7443 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7443 Version-
AmdEpyc 7443p Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7443p Version-
AmdEpyc 74f3 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 74f3 Version-
AmdEpyc 7453 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7453 Version-
AmdEpyc 7473x Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7473x Version-
AmdEpyc 7513 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7513 Version-
AmdEpyc 7543 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7543 Version-
AmdEpyc 7543p Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7543p Version-
AmdEpyc 75f3 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 75f3 Version-
AmdEpyc 7573x Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7573x Version-
AmdEpyc 7643 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7643 Version-
AmdEpyc 7773x Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7773x Version-
AmdEpyc 7643p Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7643p Version-
AmdEpyc 7663 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7663 Version-
AmdEpyc 7663p Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7663p Version-
AmdEpyc 7713 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7713 Version-
AmdEpyc 7713p Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7713p Version-
AmdEpyc 7763 Firmware Version < milanpi_1.0.0.5
   AmdEpyc 7763 Version-
AmdEpyc 7h12 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7h12 Version-
AmdEpyc 7f72 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7f72 Version-
AmdEpyc 7f52 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7f52 Version-
AmdEpyc 7f32 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7f32 Version-
AmdEpyc 7742 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7742 Version-
AmdEpyc 7702p Firmware Version < romepi_1.0.0.g
   AmdEpyc 7702p Version-
AmdEpyc 7702 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7702 Version-
AmdEpyc 7662 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7662 Version-
AmdEpyc 7642 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7642 Version-
AmdEpyc 7552 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7552 Version-
AmdEpyc 7542 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7542 Version-
AmdEpyc 7532 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7532 Version-
AmdEpyc 7502p Firmware Version < romepi_1.0.0.g
   AmdEpyc 7502p Version-
AmdEpyc 7502 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7502 Version-
AmdEpyc 7452 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7452 Version-
AmdEpyc 7402p Firmware Version < romepi_1.0.0.g
   AmdEpyc 7402p Version-
AmdEpyc 7402 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7402 Version-
AmdEpyc 7352 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7352 Version-
AmdEpyc 7302p Firmware Version < romepi_1.0.0.g
   AmdEpyc 7302p Version-
AmdEpyc 7302 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7302 Version-
AmdEpyc 7282 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7282 Version-
AmdEpyc 7272 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7272 Version-
AmdEpyc 7262 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7262 Version-
AmdEpyc 7252 Firmware Version < romepi_1.0.0.g
   AmdEpyc 7252 Version-
AmdEpyc 7232p Firmware Version < romepi_1.0.0.g
   AmdEpyc 7232p Version-
AmdEpyc 7601 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7601 Version-
AmdEpyc 7551p Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7551p Version-
AmdEpyc 7551 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7551 Version-
AmdEpyc 7501 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7501 Version-
AmdEpyc 7451 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7451 Version-
AmdEpyc 7401p Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7401p Version-
AmdEpyc 7401 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7401 Version-
AmdEpyc 7371 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7371 Version-
AmdEpyc 7351p Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7351p Version-
AmdEpyc 7351 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7351 Version-
AmdEpyc 7301 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7301 Version-
AmdEpyc 7281 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7281 Version-
AmdEpyc 7261 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7261 Version-
AmdEpyc 7251 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7251 Version-
AmdEpyc 7001 Firmware Version < naplespi_1.0.0.k
   AmdEpyc 7001 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.05% 0.157
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 6.4 0.5 5.9
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
psirt@amd.com 7.5 0.8 6
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition

The product checks the state of a resource before using that resource, but the resource's state can change between the check and the use in a way that invalidates the results of the check. This can cause the product to perform invalid actions when the resource is in an unexpected state.