CVE-2023-31352

MEDIUM

AMD EPYC 9004 Processors - Unauthorized Memory Read via SEV Firmware

Title source: llm
STIX 2.1

Description

A bug in the SEV firmware may allow an attacker with privileges to read unencrypted memory, potentially resulting in loss of guest private data.

Scores

CVSS v3 6.0
EPSS 0.0007
EPSS Percentile 20.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-119
Status published
Products (3)
AMD/AMD EPYC™ 9004 Processors GenoaPI 1.0.0.C
AMD/AMD EPYC™ 9004 Processors SEV FW1.55.36
AMD/AMD EPYC™ Embedded 9004 EmbGenoaPI-SP5 1.0.0.7
Published Feb 11, 2025
Tracked Since Feb 18, 2026