MEDIUM · 6.0

CVE-2023-20579

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability....

Vulnerability Description

Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability.

CVSS Score

6.0

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AmdRyzen 7 5700G Firmware< comboam4v2pi_1.2.0.c
AmdRyzen 7 5700G-
AmdRyzen 7 5700Ge Firmware< comboam4v2pi_1.2.0.c
AmdRyzen 7 5700Ge-
AmdRyzen 5 5600G Firmware< comboam4v2pi_1.2.0.c
AmdRyzen 5 5600G-
AmdRyzen 5 5600Gt Firmware< comboam4v2pi_1.2.0.c
AmdRyzen 5 5600Gt-
AmdRyzen 5 5600Ge Firmware< comboam4v2pi_1.2.0.c
AmdRyzen 5 5600Ge-
AmdRyzen 5 5500Gt Firmware< comboam4v2pi_1.2.0.c
AmdRyzen 5 5500Gt-
AmdRyzen 3 5300G Firmware< comboam4v2pi_1.2.0.c
AmdRyzen 3 5300G-
AmdRyzen 3 5300Ge Firmware< comboam4v2pi_1.2.0.c
AmdRyzen 3 5300Ge-
AmdRyzen 5 7500F Firmware< comboam5_1.0.8.0
AmdRyzen 5 7500F-
AmdRyzen 5 Pro 7645 Firmware< comboam5_1.0.8.0
AmdRyzen 5 Pro 7645-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20579?

CVE-2023-20579 is a vulnerability with a CVSS score of 6.0 (MEDIUM). Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability....

How severe is CVE-2023-20579?

CVE-2023-20579 has been rated MEDIUM with a CVSS base score of 6.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20579?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 7 5700G Firmware, Amd Ryzen 7 5700G, Amd Ryzen 7 5700Ge Firmware, Amd Ryzen 7 5700Ge, Amd Ryzen 5 5600G Firmware.