CVE-2020-12954

MEDIUM

Integrated Chipset Option - Privilege Escalation

Title source: llm

Description

A side effect of an integrated chipset option may be able to be used by an attacker to bypass SPI ROM protections, allowing unauthorized SPI ROM modification.

Scores

CVSS v3 5.5
EPSS 0.0006
EPSS Percentile 17.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

Classification

CWE
CWE-693
Status published

Affected Products (50)

amd/epyc_7003_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7002_firmware < romepi-sp3_1.0.0.c
amd/epyc_7001_firmware < naplespi-sp3_1.0.0.g
amd/epyc_72f3_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7313_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7313p_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7343_firmware < milanpi-sp3_1.0.0.4
amd/epyc_73f3_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7413_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7443_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7443p_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7453_firmware < milanpi-sp3_1.0.0.4
amd/epyc_74f3_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7513_firmware < milanpi-sp3_1.0.0.4
amd/epyc_7543_firmware < milanpi-sp3_1.0.0.4
... and 35 more

Timeline

Published Nov 16, 2021
Tracked Since Feb 18, 2026