Vulnerability Description
Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Radeon Software | < 23.12.1 |
| Amd | Radeon Rx 6300M | - |
| Amd | Radeon Rx 6400 | - |
| Amd | Radeon Rx 6450M | - |
| Amd | Radeon Rx 6500 Xt | - |
| Amd | Radeon Rx 6500M | - |
| Amd | Radeon Rx 6550M | - |
| Amd | Radeon Rx 6550S | - |
| Amd | Radeon Rx 6600 | - |
| Amd | Radeon Rx 6600 Xt | - |
| Amd | Radeon Rx 6600M | - |
| Amd | Radeon Rx 6600S | - |
| Amd | Radeon Rx 6650 Xt | - |
| Amd | Radeon Rx 6650M | - |
| Amd | Radeon Rx 6650M Xt | - |
| Amd | Radeon Rx 6700 | - |
| Amd | Radeon Rx 6700 Xt | - |
| Amd | Radeon Rx 6700M | - |
| Amd | Radeon Rx 6700S | - |
| Amd | Radeon Rx 6750 Gre | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2023-31307?
CVE-2023-31307 is a vulnerability with a CVSS score of 2.3 (LOW). Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.
How severe is CVE-2023-31307?
CVE-2023-31307 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-31307?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Radeon Software, Amd Radeon Rx 6300M, Amd Radeon Rx 6400, Amd Radeon Rx 6450M, Amd Radeon Rx 6500 Xt.