SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-20588

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality.

MEDIUM 5.5EPSS 11.3%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 11.3%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

A division-by-zero error on some AMD processors can potentially return speculative data resulting in loss of confidentiality. 

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
11.32% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-369
Affected
debian/debian linux · amd/epyc 7351p firmware · amd/epyc 7401p firmware · amd/epyc 7551p firmware · amd/epyc 7251 firmware · amd/epyc 7261 firmware · amd/epyc 7281 firmware · amd/epyc 7301 firmware · amd/epyc 7351 firmware · amd/epyc 7371 firmware · amd/epyc 7401 firmware · amd/epyc 7451 firmware · amd/epyc 7501 firmware · amd/epyc 7551 firmware · amd/epyc 7571 firmware · amd/epyc 7601 firmware · amd/ryzen 5 pro 3400g firmware · amd/ryzen 5 3400g firmware · amd/ryzen 5 pro 3400ge firmware · amd/ryzen 5 pro 3350g firmware · +27 more
Source
psirt@amd.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.