4.4

CVE-2023-31356

Incomplete system memory cleanup in SEV firmware could
allow a privileged attacker to corrupt guest private memory, potentially
resulting in a loss of data integrity.

Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
VendorAMD
Product AMD EPYC™ 7003 Processors
Default Statusaffected
Version MilanPI 1.0.0.C
Status unaffected
VendorAMD
Product AMD EPYC™ 9004 Processors
Default Statusaffected
Version GenoaPI 1.0.0.B
Status unaffected
VendorAMD
Product AMD EPYC™ Embedded 7003
Default Statusaffected
Version "EmbMilanPI-SP3 1.0.0.8"
Status unaffected
VendorAMD
Product AMD EPYC™ Embedded 9004
Default Statusaffected
Version EmbGenoaPI-SP5 1.0.0.6
Status unaffected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.04% 0.103
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
psirt@amd.com 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
CWE-459 Incomplete Cleanup

The product does not properly "clean up" and remove temporary or supporting resources after they have been used.