CVE-2023-20578

high-risk
Published 2024-08-13

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.

Do I need to act?

-
0.08% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.5/10 High
LOCAL / HIGH complexity

Affected Products (20)

Epyc 8024Pn Firmware
Epyc 8024P Firmware
Epyc 8124Pn Firmware
Epyc 8124P Firmware
Epyc 8224Pn Firmware
Epyc 8224P Firmware
Epyc 8324Pn Firmware
Epyc 8324P Firmware
Epyc 8434Pn Firmware
Epyc 8434P Firmware
Epyc 8534Pn Firmware
Epyc 8534P Firmware
Epyc 9734 Firmware
Epyc 9754S Firmware
Epyc 9754 Firmware
Epyc 9184X Firmware
Epyc 9384X Firmware
Epyc 9684X Firmware
Epyc 9124 Firmware
Epyc 9174F Firmware

Affected Vendors

Amd
50
/ 100
high-risk
Severity 20/34 · Moderate
Exploitability 0/34 · Minimal
Exposure 30/34 · Critical