Vulnerability Description
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 3 3300 Firmware | < comboam4_pi_v1_1.0.0.a |
| Amd | Ryzen 3 3300 | - |
| Amd | Ryzen 3 3300X Firmware | < comboam4_pi_v1_1.0.0.a |
| Amd | Ryzen 3 3300X | - |
| Amd | Ryzen 5 3600 Firmware | < comboam4_pi_v1_1.0.0.a |
| Amd | Ryzen 5 3600 | - |
| Amd | Ryzen 5 3600X Firmware | < comboam4_pi_v1_1.0.0.a |
| Amd | Ryzen 5 3600X | - |
| Amd | Ryzen 7 3700 Firmware | < comboam4_pi_v1_1.0.0.a |
| Amd | Ryzen 7 3700 | - |
| Amd | Ryzen 7 3700X Firmware | < comboam4_pi_v1_1.0.0.a |
| Amd | Ryzen 7 3700X | - |
| Amd | Ryzen 9 3800X Firmware | < comboam4_pi_v1_1.0.0.a |
| Amd | Ryzen 9 3800X | - |
| Amd | Ryzen 9 3850X Firmware | < comboam4_pi_v1_1.0.0.a |
| Amd | Ryzen 9 3850X | - |
| Amd | Ryzen 9 5950X Firmware | < comboam4_v2_pi_1.2.0.a |
| Amd | Ryzen 9 5950X | - |
| Amd | Ryzen 9 5900X Firmware | < comboam4_v2_pi_1.2.0.a |
| Amd | Ryzen 9 5900X | - |
Related Weaknesses (CWE)
References
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4003Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4003Vendor Advisory
FAQ
What is CVE-2023-20555?
CVE-2023-20555 is a vulnerability with a CVSS score of 7.8 (HIGH). Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary cod...
How severe is CVE-2023-20555?
CVE-2023-20555 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-20555?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 3 3300 Firmware, Amd Ryzen 3 3300, Amd Ryzen 3 3300X Firmware, Amd Ryzen 3 3300X, Amd Ryzen 5 3600 Firmware.