First published: Tue Aug 13 2024(Updated: )
Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Amd Athlon Silver 3050u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Athlon Silver 3050u | ||
All of | ||
Amd Athlon Gold 3150u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Athlon Gold 3150u | ||
All of | ||
Amd Ryzen 7 3780u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 7 3780u | ||
All of | ||
Amd Ryzen 7 3750h Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 7 3750h | ||
All of | ||
Amd Ryzen 7 Pro 3700u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 7 Pro 3700u | ||
All of | ||
Amd Ryzen 7 3700u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 7 3700u | ||
All of | ||
Amd Ryzen 5 3580u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 5 3580u | ||
All of | ||
Amd Ryzen 5 3550h Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 5 3550h | ||
All of | ||
Amd Ryzen 5 3500u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 5 3500u | ||
All of | ||
Amd Ryzen 3 3300u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 3 3300u | ||
All of | ||
Amd Ryzen 3 3250u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 3 3250u | ||
All of | ||
Amd Ryzen 3 3200u Firmware | <picassopi-fp5_1.0.0.e | |
Amd Ryzen 3 3200u | ||
All of | ||
Amd Athlon Gold Pro 3150g Firmware | ||
Amd Athlon Gold Pro 3150g | ||
All of | ||
Amd Athlon Gold 3150g Firmware | ||
Amd Athlon Gold 3150g | ||
All of | ||
Amd Athlon Gold Pro 3150ge Firmware | ||
Amd Athlon Gold Pro 3150ge | ||
All of | ||
Amd Athlon Pro 300ge Firmware | ||
Amd Athlon Pro 300ge |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-23815 is classified as a high severity vulnerability due to potential arbitrary code execution.
To fix CVE-2022-23815, update the firmware of the affected AMD processors to the version above picassopi-fp5_1.0.0.e.
CVE-2022-23815 impacts various AMD Athlon and Ryzen processors with specific firmware versions.
CVE-2022-23815 allows an attacker to perform an out-of-bounds write, which can lead to arbitrary code execution.
If your device uses affected AMD firmware versions listed under CVE-2022-23815, it is vulnerable.