CVE-2023-20555

HIGH

AMD Ryzen Firmware < comboam4_pi_v1_1.0.0.a & < comboam4_v2_pi_1.2.0.a - Out-of-bounds Write

Title source: llm
STIX 2.1

Description

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-787
Status published
Products (50)
amd/athlon_3015ce_firmware < pollockpi-ft5_1.0.0.5
amd/athlon_3015e_firmware < pollockpi-ft5_1.0.0.5
amd/athlon_gold_3150c_firmware < picassopi-fp5_1.0.0.f
amd/athlon_gold_3150g_firmware < comboam4piv1_1.0.0.a
amd/athlon_gold_3150ge_firmware < comboam4piv1_1.0.0.a
amd/athlon_gold_3150u_firmware < picassopi-fp5_1.0.0.f
amd/athlon_gold_pro_3150g_firmware < comboam4piv1_1.0.0.a
amd/athlon_gold_pro_3150ge_firmware < comboam4piv1_1.0.0.a
amd/athlon_pro_300ge_firmware < comboam4piv1_1.0.0.a
amd/athlon_pro_3045b_firmware < picassopi-fp5_1.0.0.f
... and 40 more
Published Aug 08, 2023
Tracked Since Feb 18, 2026