Vulnerability Description
Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 7 5700G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 7 5700G | - |
| Amd | Ryzen 7 5700Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 7 5700Ge | - |
| Amd | Ryzen 5 5600G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 5 5600G | - |
| Amd | Ryzen 5 5600Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 5 5600Ge | - |
| Amd | Ryzen 3 5300G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 3 5300G | - |
| Amd | Ryzen 3 5300Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 3 5300Ge | - |
| Amd | Ryzen 9 5980Hx Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5980Hx | - |
| Amd | Ryzen 9 5980Hs Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5980Hs | - |
| Amd | Ryzen 7 5825U Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 7 5825U | - |
| Amd | Ryzen 9 5900Hx Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5900Hx | - |
Related Weaknesses (CWE)
References
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-1027.htmlVendor Advisory
- https://www.amd.com/en/resources/product-security/bulletin/amd-sb-1027.htmlVendor Advisory
FAQ
What is CVE-2023-20559?
CVE-2023-20559 is a vulnerability with a CVSS score of 8.8 (HIGH). Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
How severe is CVE-2023-20559?
CVE-2023-20559 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-20559?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 7 5700G Firmware, Amd Ryzen 7 5700G, Amd Ryzen 7 5700Ge Firmware, Amd Ryzen 7 5700Ge, Amd Ryzen 5 5600G Firmware.