MEDIUM · 4.8

CVE-2023-31339

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage an...

Vulnerability Description

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.

CVSS Score

4.8

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
AmdTrusted Firmware-A< 2023.2
ArmTrusted Firmware-A< 2.10.1
AmdZu11Eg-
AmdZu15Eg-
AmdZu17Eg-
AmdZu19Eg-
AmdZu1Cg-
AmdZu1Eg-
AmdZu21Dr-
AmdZu25Dr-
AmdZu27Dr-
AmdZu28Dr-
AmdZu29Dr-
AmdZu2Cg-
AmdZu2Eg-
AmdZu39Dr-
AmdZu3Cg-
AmdZu3Eg-
AmdZu3Tcg-
AmdZu3Teg-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-31339?

CVE-2023-31339 is a vulnerability with a CVSS score of 4.8 (MEDIUM). Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage an...

How severe is CVE-2023-31339?

CVE-2023-31339 has been rated MEDIUM with a CVSS base score of 4.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-31339?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Trusted Firmware-A, Arm Trusted Firmware-A, Amd Zu11Eg, Amd Zu15Eg, Amd Zu17Eg.