HIGH · 7.8

CVE-2023-20555

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary cod...

Vulnerability Description

Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.

CVSS Score

7.8

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AmdRyzen 3 3300 Firmware< comboam4_pi_v1_1.0.0.a
AmdRyzen 3 3300-
AmdRyzen 3 3300X Firmware< comboam4_pi_v1_1.0.0.a
AmdRyzen 3 3300X-
AmdRyzen 5 3600 Firmware< comboam4_pi_v1_1.0.0.a
AmdRyzen 5 3600-
AmdRyzen 5 3600X Firmware< comboam4_pi_v1_1.0.0.a
AmdRyzen 5 3600X-
AmdRyzen 7 3700 Firmware< comboam4_pi_v1_1.0.0.a
AmdRyzen 7 3700-
AmdRyzen 7 3700X Firmware< comboam4_pi_v1_1.0.0.a
AmdRyzen 7 3700X-
AmdRyzen 9 3800X Firmware< comboam4_pi_v1_1.0.0.a
AmdRyzen 9 3800X-
AmdRyzen 9 3850X Firmware< comboam4_pi_v1_1.0.0.a
AmdRyzen 9 3850X-
AmdRyzen 9 5950X Firmware< comboam4_v2_pi_1.2.0.a
AmdRyzen 9 5950X-
AmdRyzen 9 5900X Firmware< comboam4_v2_pi_1.2.0.a
AmdRyzen 9 5900X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20555?

CVE-2023-20555 is a vulnerability with a CVSS score of 7.8 (HIGH). Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary cod...

How severe is CVE-2023-20555?

CVE-2023-20555 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20555?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 3 3300 Firmware, Amd Ryzen 3 3300, Amd Ryzen 3 3300X Firmware, Amd Ryzen 3 3300X, Amd Ryzen 5 3600 Firmware.