CVE Vulnerabilities

CVE-2022-23821

Published: Nov 14, 2023 | Modified: Feb 13, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper access control in System Management Mode (SMM) may allow an attacker to write to SPI ROM potentially leading to arbitrary code execution.

Affected Software

Name Vendor Start Version End Version
Ryzen_9_3900_firmware Amd comboam4_pi_1.0.0.9 (including) comboam4_pi_1.0.0.9 (including)
Ryzen_9_3900_firmware Amd comboam4_v2_pi_1.2.0.8 (including) comboam4_v2_pi_1.2.0.8 (including)

References