CVE-2022-23823

MEDIUM

AMD Athlon X4/Ryzen Threadripper PRO Firmware Info Disclosure via Timing Attack

Title source: llm
STIX 2.1

Description

A potential vulnerability in some AMD processors using frequency scaling may allow an authenticated attacker to execute a timing attack to potentially enable information disclosure.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0082
EPSS Percentile 74.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-203
Status published
Products (50)
amd/a10-9600p_firmware
amd/a10-9630p_firmware
amd/a12-9700p_firmware
amd/a12-9730p_firmware
amd/a4-9120_firmware
amd/a6-9210_firmware
amd/a6-9220_firmware
amd/a6-9220c_firmware
amd/a9-9410_firmware
amd/a9-9420_firmware
... and 40 more
Published Jun 15, 2022
Tracked Since Feb 18, 2026