CVE-2023-20578

HIGH

AMD EPYC Firmware < genoapi_1.0.0.2 - Authenticated TOCTOU Race Condition in SMM

Title source: llm
STIX 2.1

Description

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0008
EPSS Percentile 22.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-367
Status published
Products (50)
amd/epyc_7001_firmware < naplespi_1.0.0.k
amd/epyc_7203_firmware < milanpi_1.0.0.5
amd/epyc_7203p_firmware < milanpi_1.0.0.5
amd/epyc_7232p_firmware < romepi_1.0.0.g
amd/epyc_7251_firmware < naplespi_1.0.0.k
amd/epyc_7252_firmware < romepi_1.0.0.g
amd/epyc_7261_firmware < naplespi_1.0.0.k
amd/epyc_7262_firmware < romepi_1.0.0.g
amd/epyc_7272_firmware < romepi_1.0.0.g
amd/epyc_7281_firmware < naplespi_1.0.0.k
... and 40 more
Published Aug 13, 2024
Tracked Since Feb 18, 2026