CVE-2023-31331
Published: Feb 11, 2025
Modified: Feb 12, 2025
CVSS v3.1
3.0
Description
Improper access control in the DRTM firmware could allow a privileged attacker to perform multiple driver initializations, resulting in stack memory corruption that could potentially lead to loss of integrity or availability.
| Vendor | Product | Versions |
|---|---|---|
AMD | AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics | unaffected ComboAM4v2PI 1.2.0.CA |
AMD | AMD Ryzen™ 7000 Series Desktop Processors | unaffected ComboAM5 1.1.0.2 |
AMD | AMD Ryzen™ 4000 Series Desktop Processor with Radeon™ Graphics | unaffected ComboAM4v2PI 1.2.0.CA |
AMD | AMD Ryzen™ 8000 Series Processor with Radeon™ Graphics | unaffected ComboAM5 1.1.0.2 |
AMD | AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics | unaffected RenoirPI-FP6 1.0.0.D |
AMD | AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics | unaffected Cezanne-FP6 1.0.1.0 |
AMD | AMD Ryzen™ 6000 Series Processor with Radeon™ Graphics | unaffected Rembrandt-FP7 1.0.0.A |
AMD | AMD Ryzen™ 7035 Series Processor with Radeon™ Graphics | unaffected Rembrandt-FP7 1.0.0.A |
AMD | AMD Ryzen™ 7040 Series Processors with Radeon™ Graphics | unaffected PhoenixPI-FP8-FP7 1.1.0.2 |
AMD | AMD Ryzen™ 8040 Series Mobile Processors with Radeon™ Graphics | unaffected PhoenixPI-FP8-FP7 1.1.0.2 |
AMD | AMD Ryzen™ 7000 Series Mobile Processors | unaffected DragonRangeFL1PI 1.0.0.3C |
AMD | AMD Ryzen™ Embedded 7000 | unaffected EmbeddedAM5PI 1.0.0.1 |
AMD | AMD Ryzen™ Embedded V2000 | unaffected EmbeddedPI-FP6 1.0.0.9 |
AMD | AMD Ryzen™ Embedded V3000 | unaffected Embedded-PI FP7r2 1.0.0.9 |
Weaknesses (CWE)
CVSS v3.1 Details
CVSS v3.1 Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:L
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now