CVE-2023-20526

Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:amd:epyc_7001_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7001:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:amd:epyc_7251_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7251:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:amd:epyc_7261_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7261:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:amd:epyc_7281_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7281:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:amd:epyc_7301_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7301:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:amd:epyc_7351_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7351:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:amd:epyc_7351p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7351p:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:amd:epyc_7371_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7371:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:amd:epyc_7401_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7401:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:amd:epyc_7401p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7401p:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:amd:epyc_7451_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7451:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:amd:epyc_7501_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7501:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:amd:epyc_7551_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7551:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:amd:epyc_7551p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7551p:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:amd:epyc_7601_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7601:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:amd:epyc_7232p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7232p:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:amd:epyc_7252_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7252:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:amd:epyc_7262_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7262:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:amd:epyc_7272_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7272:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:amd:epyc_7282_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7282:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:amd:epyc_7302_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7302:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:amd:epyc_7302p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7302p:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:amd:epyc_7352_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7352:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:amd:epyc_7402_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7402:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:amd:epyc_7402p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7402p:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:amd:epyc_7452_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7452:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:amd:epyc_7502_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7502:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:amd:epyc_7502p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7502p:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:amd:epyc_7532_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7532:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:amd:epyc_7542_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7542:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:amd:epyc_7552_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7552:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:amd:epyc_7642_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7642:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:amd:epyc_7662_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7662:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:amd:epyc_7702_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7702:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:amd:epyc_7702p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7702p:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:amd:epyc_7742_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7742:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:amd:epyc_7f32_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7f32:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:amd:epyc_7f52_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7f52:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:amd:epyc_7f72_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7f72:-:*:*:*:*:*:*:*

Configuration 40 (hide)

AND
cpe:2.3:o:amd:epyc_7h12_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7h12:-:*:*:*:*:*:*:*

Configuration 41 (hide)

AND
cpe:2.3:o:amd:epyc_7763_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7763:-:*:*:*:*:*:*:*

Configuration 42 (hide)

AND
cpe:2.3:o:amd:epyc_7713p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7713p:-:*:*:*:*:*:*:*

Configuration 43 (hide)

AND
cpe:2.3:o:amd:epyc_7713_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7713:-:*:*:*:*:*:*:*

Configuration 44 (hide)

AND
cpe:2.3:o:amd:epyc_7663p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7663p:-:*:*:*:*:*:*:*

Configuration 45 (hide)

AND
cpe:2.3:o:amd:epyc_7663_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7663:-:*:*:*:*:*:*:*

Configuration 46 (hide)

AND
cpe:2.3:o:amd:epyc_7643p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7643p:-:*:*:*:*:*:*:*

Configuration 47 (hide)

AND
cpe:2.3:o:amd:epyc_7773x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7773x:-:*:*:*:*:*:*:*

Configuration 48 (hide)

AND
cpe:2.3:o:amd:epyc_7643_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7643:-:*:*:*:*:*:*:*

Configuration 49 (hide)

AND
cpe:2.3:o:amd:epyc_7573x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7573x:-:*:*:*:*:*:*:*

Configuration 50 (hide)

AND
cpe:2.3:o:amd:epyc_75f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_75f3:-:*:*:*:*:*:*:*

Configuration 51 (hide)

AND
cpe:2.3:o:amd:epyc_7543p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7543p:-:*:*:*:*:*:*:*

Configuration 52 (hide)

AND
cpe:2.3:o:amd:epyc_7543_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7543:-:*:*:*:*:*:*:*

Configuration 53 (hide)

AND
cpe:2.3:o:amd:epyc_7513_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7513:-:*:*:*:*:*:*:*

Configuration 54 (hide)

AND
cpe:2.3:o:amd:epyc_7473x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7473x:-:*:*:*:*:*:*:*

Configuration 55 (hide)

AND
cpe:2.3:o:amd:epyc_7453_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7453:-:*:*:*:*:*:*:*

Configuration 56 (hide)

AND
cpe:2.3:o:amd:epyc_74f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_74f3:-:*:*:*:*:*:*:*

Configuration 57 (hide)

AND
cpe:2.3:o:amd:epyc_7443p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7443p:-:*:*:*:*:*:*:*

Configuration 58 (hide)

AND
cpe:2.3:o:amd:epyc_7443_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7443:-:*:*:*:*:*:*:*

Configuration 59 (hide)

AND
cpe:2.3:o:amd:epyc_7413_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7413:-:*:*:*:*:*:*:*

Configuration 60 (hide)

AND
cpe:2.3:o:amd:epyc_7373x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7373x:-:*:*:*:*:*:*:*

Configuration 61 (hide)

AND
cpe:2.3:o:amd:epyc_73f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_73f3:-:*:*:*:*:*:*:*

Configuration 62 (hide)

AND
cpe:2.3:o:amd:epyc_7343_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7343:-:*:*:*:*:*:*:*

Configuration 63 (hide)

AND
cpe:2.3:o:amd:epyc_7313p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7313p:-:*:*:*:*:*:*:*

Configuration 64 (hide)

AND
cpe:2.3:o:amd:epyc_7313_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7313:-:*:*:*:*:*:*:*

Configuration 65 (hide)

AND
cpe:2.3:o:amd:epyc_7303p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7303p:-:*:*:*:*:*:*:*

Configuration 66 (hide)

AND
cpe:2.3:o:amd:epyc_7303_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7303:-:*:*:*:*:*:*:*

Configuration 67 (hide)

AND
cpe:2.3:o:amd:epyc_72f3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_72f3:-:*:*:*:*:*:*:*

Configuration 68 (hide)

AND
cpe:2.3:o:amd:epyc_7203p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7203p:-:*:*:*:*:*:*:*

Configuration 69 (hide)

AND
cpe:2.3:o:amd:epyc_7203_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:epyc_7203:-:*:*:*:*:*:*:*

Configuration 70 (hide)

AND
cpe:2.3:o:amd:ryzen_threadripper_2990wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_2990wx:-:*:*:*:*:*:*:*

Configuration 71 (hide)

AND
cpe:2.3:o:amd:ryzen_threadripper_2970wx_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_2970wx:-:*:*:*:*:*:*:*

Configuration 72 (hide)

AND
cpe:2.3:o:amd:ryzen_threadripper_2950x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_2950x:-:*:*:*:*:*:*:*

Configuration 73 (hide)

AND
cpe:2.3:o:amd:ryzen_threadripper_2920x_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_threadripper_2920x:-:*:*:*:*:*:*:*

History

18 Jun 2024, 19:15

Type Values Removed Values Added
Summary (en) Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality. (en) Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.

13 Feb 2024, 20:15

Type Values Removed Values Added
References
  • () https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-5001 -

27 Nov 2023, 18:53

Type Values Removed Values Added
New CVE

Information

Published : 2023-11-14 19:15

Updated : 2024-06-18 19:15


NVD link : CVE-2023-20526

Mitre link : CVE-2023-20526

CVE.ORG link : CVE-2023-20526


JSON object : View

Products Affected

amd

  • epyc_7713_firmware
  • epyc_7261_firmware
  • epyc_7513
  • epyc_7282
  • epyc_7532_firmware
  • epyc_7663
  • epyc_7371
  • epyc_7302p_firmware
  • epyc_7532
  • epyc_7643_firmware
  • epyc_7351
  • epyc_7773x
  • epyc_7251_firmware
  • epyc_7451_firmware
  • epyc_7543
  • epyc_7551p_firmware
  • epyc_7702_firmware
  • epyc_7343
  • epyc_7601
  • epyc_7303_firmware
  • ryzen_threadripper_2950x_firmware
  • epyc_7f52_firmware
  • epyc_7203p_firmware
  • epyc_7702
  • epyc_7001
  • epyc_73f3_firmware
  • epyc_75f3_firmware
  • epyc_7h12
  • epyc_7313
  • epyc_7551_firmware
  • epyc_7662
  • epyc_7573x
  • ryzen_threadripper_2970wx_firmware
  • epyc_7251
  • epyc_73f3
  • epyc_7502_firmware
  • epyc_7402_firmware
  • epyc_7501_firmware
  • epyc_7402p_firmware
  • epyc_7662_firmware
  • epyc_7f32_firmware
  • epyc_7302
  • epyc_7453
  • epyc_7443p
  • epyc_7642
  • epyc_7351p
  • epyc_7282_firmware
  • epyc_74f3_firmware
  • epyc_7542
  • epyc_7713p
  • epyc_7402p
  • epyc_7473x
  • epyc_7501
  • epyc_7303p_firmware
  • epyc_7373x_firmware
  • epyc_72f3
  • epyc_7313p
  • epyc_7352
  • epyc_7473x_firmware
  • epyc_7001_firmware
  • epyc_7232p_firmware
  • epyc_7f72_firmware
  • epyc_7713
  • epyc_7452_firmware
  • epyc_7773x_firmware
  • epyc_7232p
  • epyc_7443
  • epyc_7601_firmware
  • epyc_7763
  • epyc_7643p
  • epyc_7502p_firmware
  • epyc_7551
  • epyc_7281
  • epyc_7352_firmware
  • epyc_7313p_firmware
  • epyc_7401
  • epyc_7262_firmware
  • epyc_7643
  • epyc_7413_firmware
  • epyc_7443p_firmware
  • epyc_7663p
  • epyc_7451
  • epyc_7281_firmware
  • epyc_72f3_firmware
  • epyc_7452
  • epyc_7763_firmware
  • epyc_7453_firmware
  • epyc_7543p
  • epyc_7542_firmware
  • epyc_7261
  • epyc_7742
  • ryzen_threadripper_2970wx
  • epyc_7643p_firmware
  • epyc_7303p
  • epyc_7301_firmware
  • epyc_7543_firmware
  • epyc_7401p_firmware
  • epyc_75f3
  • epyc_7f72
  • epyc_7203_firmware
  • epyc_7552_firmware
  • epyc_7272
  • epyc_7f32
  • epyc_7262
  • epyc_7h12_firmware
  • epyc_7351p_firmware
  • epyc_7413
  • epyc_7373x
  • epyc_7252
  • epyc_7502p
  • epyc_7302p
  • ryzen_threadripper_2920x
  • epyc_7203p
  • epyc_7551p
  • epyc_7252_firmware
  • epyc_7552
  • epyc_7642_firmware
  • epyc_7702p
  • epyc_7f52
  • epyc_74f3
  • epyc_7272_firmware
  • epyc_7313_firmware
  • epyc_7663_firmware
  • epyc_7401p
  • epyc_7351_firmware
  • epyc_7402
  • epyc_7713p_firmware
  • ryzen_threadripper_2920x_firmware
  • epyc_7303
  • ryzen_threadripper_2950x
  • epyc_7573x_firmware
  • epyc_7513_firmware
  • epyc_7302_firmware
  • epyc_7443_firmware
  • ryzen_threadripper_2990wx
  • epyc_7502
  • ryzen_threadripper_2990wx_firmware
  • epyc_7663p_firmware
  • epyc_7371_firmware
  • epyc_7543p_firmware
  • epyc_7401_firmware
  • epyc_7742_firmware
  • epyc_7301
  • epyc_7343_firmware
  • epyc_7203
  • epyc_7702p_firmware