SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-20593

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

MEDIUM 5.5EPSS 5.19%

Does this matter?

Lower severity and a low EPSS score (5.19%). Track it; it rarely justifies an emergency change on its own.

Description

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
5.19% probability · 92th percentile
CISA KEV
Not listed
Weakness
CWE-209
Affected
xen/xen · debian/debian linux · amd/ryzen 3 3100 firmware · amd/ryzen 3 3300x firmware · amd/ryzen 5 3500 firmware · amd/ryzen 5 3500x firmware · amd/ryzen 5 3600 firmware · amd/ryzen 5 3600x firmware · amd/ryzen 5 3600xt firmware · amd/ryzen 7 3700x firmware · amd/ryzen 7 3800x firmware · amd/ryzen 7 3800xt firmware · amd/ryzen 9 3900 firmware · amd/ryzen 9 3900x firmware · amd/ryzen 9 3900xt firmware · amd/ryzen 9 3950x firmware · amd/ryzen 9 pro 3900 firmware · amd/ryzen threadripper pro 3995wx firmware · amd/ryzen threadripper pro 3975wx firmware · amd/ryzen threadripper pro 3955wx firmware · +40 more
Source
psirt@amd.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.