CVE Vulnerabilities

CVE-2022-23821

Published: Nov 14, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.

Affected Software

NameVendorStart VersionEnd Version
Ryzen_9_3900_firmwareAmdcomboam4_pi_1.0.0.9 (including)comboam4_pi_1.0.0.9 (including)
Ryzen_9_3900_firmwareAmdcomboam4_v2_pi_1.2.0.8 (including)comboam4_v2_pi_1.2.0.8 (including)

References