CVE-2023-20576
massInsufficient SPI ROM Data Authenticity in AMD AGESA Firmware
CVE-2023-20576 is a CWE-345 (insufficient verification of data authenticity) flaw in AMD's AGESA platform firmware, which is the low-level initialization code shipped in the BIOS/UEFI of AMD-based systems. When SPI ROM data is updated, AGESA does not adequately verify the authenticity of that data, so an attacker with local access who is able to update SPI ROM contents can push unauthenticated changes to the firmware image. Successful abuse can result in denial of service (a corrupted or maliciously modified SPI ROM can render the system unbootable) or privilege escalation from modified firmware. The flaw affects systems running AGESA-based firmware across AMD platforms; the available data does not enumerate specific AGESA version ranges or product lines. There is currently no known public proof-of-concept, it is not listed in CISA's Known Exploited Vulnerabilities catalog, and EPSS puts 30-day exploitation probability at only about 0.1% (2nd percentile).
What to do: Because the fix is delivered through motherboard/OEM BIOS updates incorporating corrected AGESA, check your motherboard or system OEM's support page for a BIOS/firmware update addressing CVE-2023-20576 and apply it when available. Until patched, limit local access and the ability to reflash or modify SPI ROM on sensitive systems (e.g., require physical access or admin rights for firmware updates). Note that the data provided does not specify affected AGESA version ranges, so verify applicability against AMD's official advisory.
| AMD AGESA platform firmware (BIOS/UEFI on AMD-based systems, including Ryzen/EPYC-class platforms) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
- Weakness
- CWE-345
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.