ZeroHour

CVE-2023-20591

CVSS 3.1
10.0 critical
EPSS
<1%p23
Published
()
Modified
Description

Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.

Vendors
amd
Products
epyc 8024pn firmware, epyc 8024p firmware, epyc 8124pn firmware, epyc 8124p firmware, epyc 8224pn firmware, epyc 8224p firmware, epyc 8324pn firmware, epyc 8324p firmware, epyc 8434pn firmware, epyc 8434p firmware, epyc 8534pn firmware, epyc 8534p firmware
Weakness
CWE-665
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.