CVE-2023-20578
high-risk
Published 2024-08-13
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
Do I need to act?
-
0.08% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10
High
LOCAL
/ HIGH complexity
Affected Products (20)
Epyc 8024Pn Firmware
Epyc 8024P Firmware
Epyc 8124Pn Firmware
Epyc 8124P Firmware
Epyc 8224Pn Firmware
Epyc 8224P Firmware
Epyc 8324Pn Firmware
Epyc 8324P Firmware
Epyc 8434Pn Firmware
Epyc 8434P Firmware
Epyc 8534Pn Firmware
Epyc 8534P Firmware
Epyc 9734 Firmware
Epyc 9754S Firmware
Epyc 9754 Firmware
Epyc 9184X Firmware
Epyc 9384X Firmware
Epyc 9684X Firmware
Epyc 9124 Firmware
Epyc 9174F Firmware
Affected Vendors
References (1)
50
/ 100
high-risk
Severity
20/34 · Moderate
Exploitability
0/34 · Minimal
Exposure
30/34 · Critical