SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-20521

TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.

MEDIUM 5.7EPSS 0.26%

Does this matter?

Lower severity and a low EPSS score (0.26%). Track it; it rarely justifies an emergency change on its own.

Description

TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.

CVSS 3.1
5.7 MEDIUMCVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS
0.26% probability · 18th percentile
CISA KEV
Not listed
Weakness
CWE-367
Affected
amd/epyc 7001 firmware · amd/epyc 7251 firmware · amd/epyc 7261 firmware · amd/epyc 7281 firmware · amd/epyc 7301 firmware · amd/epyc 7351 firmware · amd/epyc 7351p firmware · amd/epyc 7371 firmware · amd/epyc 7401 firmware · amd/epyc 7401p firmware · amd/epyc 7451 firmware · amd/epyc 7501 firmware · amd/epyc 7551 firmware · amd/epyc 7551p firmware · amd/epyc 7601 firmware · amd/epyc 7232p firmware · amd/epyc 7252 firmware · amd/epyc 7262 firmware · amd/epyc 7272 firmware · amd/epyc 7282 firmware · +40 more
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.