CVE-2022-23820
Published: Nov 14, 2023
Modified: Aug 3, 2024
CVSS v3.1
7.5
Description
Failure to validate the AMD SMM communication buffer may allow an attacker to corrupt the SMRAM potentially leading to arbitrary code execution.
| Vendor | Product | Versions |
|---|---|---|
AMD | Ryzen™ 3000 series Desktop Processors “Matisse" | affected various |
AMD | AMD Ryzen™ 5000 Series Desktop Processors “Vermeer” | affected various |
AMD | AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics “Cezanne” | affected various |
AMD | AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics “Picasso” AM4 | affected various |
AMD | AMD Ryzen™ Threadripper™ 2000 Series Processors “Colfax” | affected Various |
AMD | AMD Ryzen™ Threadripper™ 3000 Series Processors “Castle Peak” HEDT | affected various |
AMD | AMD Ryzen™ Threadripper™ PRO Processors “Castle Peak” WS SP3 | affected various |
AMD | AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors “Chagall” WS | affected various |
AMD | AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Pollock” | affected various |
AMD | AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ Graphics “Picasso” FP5 | affected various |
AMD | AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics “Renoir” FP6 | affected various |
AMD | AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics “Lucienne” | affected various |
AMD | AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics “Cezanne” | affected various |
AMD | AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics "Rembrandt" | affected various |
AMD | AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics “Rembrandt-R” | affected various |
AMD | AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics “Barcelo” | affected various |
AMD | AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ Graphics “Barcelo-R” | affected various |
AMD | 3rd Gen AMD EPYC™ Processors | affected various |
AMD | AMD EPYC™ Embedded 7003 | affected various |
AMD | AMD EPYC™ Embedded 7003 | affected various |
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now