MEDIUM · 5.5

CVE-2023-20593

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

Vulnerability Description

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVSS Score

5.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
XenXen4.14.0
DebianDebian Linux10.0
AmdRyzen 3 3100 Firmware-
AmdRyzen 3 3100-
AmdRyzen 3 3300X Firmware-
AmdRyzen 3 3300X-
AmdRyzen 5 3500 Firmware-
AmdRyzen 5 3500-
AmdRyzen 5 3500X Firmware-
AmdRyzen 5 3500X-
AmdRyzen 5 3600 Firmware-
AmdRyzen 5 3600-
AmdRyzen 5 3600X Firmware-
AmdRyzen 5 3600X-
AmdRyzen 5 3600Xt Firmware-
AmdRyzen 5 3600Xt-
AmdRyzen 7 3700X Firmware-
AmdRyzen 7 3700X-
AmdRyzen 7 3800X Firmware-
AmdRyzen 7 3800X-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-20593?

CVE-2023-20593 is a vulnerability with a CVSS score of 5.5 (MEDIUM). An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

How severe is CVE-2023-20593?

CVE-2023-20593 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-20593?

Check the references section above for vendor advisories and patch information. Affected products include: Xen Xen, Debian Debian Linux, Amd Ryzen 3 3100 Firmware, Amd Ryzen 3 3100, Amd Ryzen 3 3300X Firmware.