CVE-2022-23820

HIGH

AMD SMM Firmware - Code Execution via Communication Buffer Validation Failure

Title source: manual
STIX 2.1

Description

Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.

Scores

CVSS v3 7.5
EPSS 0.0018
EPSS Percentile 39.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (50)
amd/athlon_3015ce_firmware pollockpi-ft5_1.0.0.5
amd/athlon_3015e_firmware pollockpi-ft5_1.0.0.5
amd/ryzen_3_3100_firmware comboam4_pi_1.0.0.9
amd/ryzen_3_3100_firmware comboam4_v2_pi_1.2.0.8
amd/ryzen_3_3300u_firmware picassopi-fp5_1.0.0.e
amd/ryzen_3_3300x_firmware comboam4_pi_1.0.0.9
amd/ryzen_3_3300x_firmware comboam4_v2_pi_1.2.0.8
amd/ryzen_3_3350u_firmware picassopi-fp5_1.0.0.e
amd/ryzen_3_4300u_firmware renoirpi-fp6_1.0.0.9
amd/ryzen_3_5100_firmware comboam4v2_pi_1.2.0.8
... and 40 more
Published Nov 14, 2023
Tracked Since Feb 18, 2026