CVE-2023-20521

LOW

AMD EPYC 7001 Series Firmware - Time-of-check Time-of-use Race Condition in ASP Bootloader

Title source: llm
STIX 2.1

Description

TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.

Scores

CVSS v3 3.3
EPSS 0.0004
EPSS Percentile 11.2%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (50)
amd/amd_3015ce_firmware < pollockpi-ft5_1.0.0.4
amd/amd_3015e_firmware < pollockpi-ft5_1.0.0.4
amd/athlon_gold_3150g_firmware
amd/athlon_gold_pro_3150g_firmware
amd/athlon_gold_pro_3150ge_firmware
amd/athlon_pro_300ge_firmware
amd/epyc_7001_firmware < naplespi_1.0.0.h
amd/epyc_7203_firmware < milanpi_1.0.0.7
amd/epyc_7203p_firmware < milanpi_1.0.0.7
amd/epyc_7232p_firmware < romepi_1.0.0.d
... and 40 more
Published Nov 14, 2023
Tracked Since Feb 18, 2026