4.4

CVE-2023-31307

Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.

Data is provided by the National Vulnerability Database (NVD)
AmdRadeon Software SwEditionadrenalin Version < 23.12.1
   AmdRadeon Rx 6300m Version-
   AmdRadeon Rx 6400 Version-
   AmdRadeon Rx 6450m Version-
   AmdRadeon Rx 6500 Xt Version-
   AmdRadeon Rx 6500m Version-
   AmdRadeon Rx 6550m Version-
   AmdRadeon Rx 6550s Version-
   AmdRadeon Rx 6600 Version-
   AmdRadeon Rx 6600 Xt Version-
   AmdRadeon Rx 6600m Version-
   AmdRadeon Rx 6600s Version-
   AmdRadeon Rx 6650 Xt Version-
   AmdRadeon Rx 6650m Version-
   AmdRadeon Rx 6650m Xt Version-
   AmdRadeon Rx 6700 Version-
   AmdRadeon Rx 6700 Xt Version-
   AmdRadeon Rx 6700m Version-
   AmdRadeon Rx 6700s Version-
   AmdRadeon Rx 6750 Gre Version-
   AmdRadeon Rx 6750 Xt Version-
   AmdRadeon Rx 6800 Version-
   AmdRadeon Rx 6800 Xt Version-
   AmdRadeon Rx 6800m Version-
   AmdRadeon Rx 6800s Version-
   AmdRadeon Rx 6850m Xt Version-
   AmdRadeon Rx 6900 Xt Version-
   AmdRadeon Rx 6950 Xt Version-
AmdRadeon Software SwEditionpro Version <= 23.q4
   AmdRadeon Pro W6300 Version-
   AmdRadeon Pro W6400 Version-
   AmdRadeon Pro W6600 Version-
   AmdRadeon Pro W6800 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.06% 0.193
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
psirt@amd.com 2.3 0.8 1.4
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L
CWE-129 Improper Validation of Array Index

The product uses untrusted input when calculating or using an array index, but the product does not validate or incorrectly validates the index to ensure the index references a valid position within the array.