ZeroHour

CVE-2023-20576

mass

Insufficient SPI ROM Data Authenticity in AMD AGESA Firmware

CVSS 3.1
7.7 high
EPSS
<1%p2
Published
()
Modified
AI analysis

CVE-2023-20576 is a CWE-345 (insufficient verification of data authenticity) flaw in AMD's AGESA platform firmware, which is the low-level initialization code shipped in the BIOS/UEFI of AMD-based systems. When SPI ROM data is updated, AGESA does not adequately verify the authenticity of that data, so an attacker with local access who is able to update SPI ROM contents can push unauthenticated changes to the firmware image. Successful abuse can result in denial of service (a corrupted or maliciously modified SPI ROM can render the system unbootable) or privilege escalation from modified firmware. The flaw affects systems running AGESA-based firmware across AMD platforms; the available data does not enumerate specific AGESA version ranges or product lines. There is currently no known public proof-of-concept, it is not listed in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at only about 0.1% (2nd percentile).

What to do: Because the fix is delivered through motherboard/OEM BIOS updates incorporating corrected AGESA, check your motherboard or system OEM's support page for a BIOS/firmware update addressing CVE-2023-20576 and apply it when available. Until patched, limit local access and the ability to reflash or modify SPI ROM on sensitive systems (e.g., require physical access or admin rights for firmware updates). Note that the data provided does not specify affected AGESA version ranges, so verify applicability against AMD's official advisory.

Affected
AMD AGESA platform firmware (BIOS/UEFI on AMD-based systems, including Ryzen/EPYC-class platforms)
Estimated exposure
masshundreds of millions of AMD-based systems (effectively any desktop/laptop/server shipping AGESA-era BIOS/UEFI) — AGESA is the common firmware foundation embedded in the BIOS/UEFI of essentially all AMD Ryzen and EPYC platforms, and AMD has shipped hundreds of millions of such processors, so the installed base carrying this component is plausibly on…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.

Weakness
CWE-345
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.