CVE-2023-20591
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.30%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.
- CVSS 3.1
- 10.0 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-665
- Affected
- amd/epyc 8024pn firmware · amd/epyc 8024p firmware · amd/epyc 8124pn firmware · amd/epyc 8124p firmware · amd/epyc 8224pn firmware · amd/epyc 8224p firmware · amd/epyc 8324pn firmware · amd/epyc 8324p firmware · amd/epyc 8434pn firmware · amd/epyc 8434p firmware · amd/epyc 8534pn firmware · amd/epyc 8534p firmware · amd/epyc 9734 firmware · amd/epyc 9754s firmware · amd/epyc 9754 firmware · amd/epyc 9184x firmware · amd/epyc 9384x firmware · amd/epyc 9684x firmware · amd/epyc 9124 firmware · amd/epyc 9174f firmware · +40 more
- Source
- psirt@amd.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.