• CVE-2023-20576

发布时间: 2024年2月27日

修改时间: 2024年2月27日

概要

A vulnerability was found in AMD hardware due to insufficient verification of data authenticity in AGESA. This issue may allow a local unauthenticated attacker to update SPI ROM data, potentially resulting in denial of service or privilege escalation.

CVSS v3 指标

NVD openEuler
CVSS评分 7.7
Attack Vector Local
Attack Complexity Low
Privileges Required None
User Interaction None
Scope Unchanged
Confidentiality High
Integrity None
Availability High

安全公告

公告名 概要 发布时间
KylinSec-SA-2024-1086 A vulnerability was found in AMD hardware due to insufficient verification of data authenticity in AGESA. This issue may allow a local unauthenticated attacker to update SPI ROM data, potentially resulting in denial of service or privilege escalation. 2024年2月27日

影响产品

产品 状态
KY3.4-4A linux-firmware Unaffected
KY3.4-5A linux-firmware Unaffected
KY3.5.1 linux-firmware Unaffected
KY3.5.2 linux-firmware Unaffected