CVE Vulnerabilities

CVE-2023-20565

Improper Privilege Management

Published: Nov 14, 2023 | Modified: Feb 13, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Insufficient protections in System Management Mode (SMM) code may allow an attacker to potentially enable escalation of privilege via local access.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Ryzen_3_5100_firmware Amd * comboam4v2_1.2.0.b (excluding)

Potential Mitigations

References