CVE-2023-20578
—CVSS 3.1
6.4 medium
EPSS
<1%p2
Published
()
Modified
Description
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
- Vendors
- amd
- Products
- epyc 8024pn firmware, epyc 8024p firmware, epyc 8124pn firmware, epyc 8124p firmware, epyc 8224pn firmware, epyc 8224p firmware, epyc 8324pn firmware, epyc 8324p firmware, epyc 8434pn firmware, epyc 8434p firmware, epyc 8534pn firmware, epyc 8534p firmware
- Weakness
- CWE-367
- Vector
- CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.