First published: Tue May 09 2023(Updated: )
Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.
Credit: psirt@amd.com psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
AMD EPYC 72F3 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 72F3 Firmware | ||
All of | ||
Amd Epyc Server Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7313P | ||
All of | ||
AMD EPYC 7313P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7313P | ||
All of | ||
Amd Epyc Server Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7343 | ||
All of | ||
AMD EPYC 7373X Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7373X | ||
All of | ||
AMD EPYC 73F3 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 73F3 | ||
All of | ||
AMD EPYC 7413 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7413 Firmware | ||
All of | ||
AMD EPYC 7443 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7443 | ||
All of | ||
AMD EPYC 7443P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7443P | ||
All of | ||
Amd Epyc Server Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7453 | ||
All of | ||
AMD EPYC 7473X Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7473X | ||
All of | ||
AMD EPYC 74F3 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 74F3 | ||
All of | ||
AMD EPYC 7513 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7513 | ||
All of | ||
Amd Epyc Server Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7543 Firmware | ||
All of | ||
AMD EPYC 7543P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7543P Firmware | ||
All of | ||
AMD EPYC 7573X Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7573X | ||
All of | ||
AMD EPYC 75F3 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 75F3 | ||
All of | ||
AMD EPYC 7643 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7643 | ||
All of | ||
AMD EPYC 7663 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7663 Firmware | ||
All of | ||
AMD EPYC 7713P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7713 | ||
All of | ||
AMD EPYC 7713P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7713P Firmware | ||
All of | ||
AMD EPYC 7763 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7763 Firmware | ||
All of | ||
AMD EPYC 7773X Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7773X | ||
All of | ||
AMD EPYC 7232p firmware | =romepi_1.0.0.d | |
AMD EPYC 7232p firmware | ||
All of | ||
AMD EPYC 7252 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7252 Firmware | ||
All of | ||
AMD EPYC 7262 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7262 Firmware | ||
All of | ||
AMD EPYC 7272 firmware | =romepi_1.0.0.d | |
AMD EPYC 7272 firmware | ||
All of | ||
AMD EPYC 7282 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7282 | ||
All of | ||
Amd Epyc Server Firmware | =romepi_1.0.0.d | |
AMD EPYC 7302P | ||
All of | ||
AMD EPYC 7302P Firmware | =romepi_1.0.0.d | |
AMD EPYC 7302P | ||
All of | ||
AMD EPYC 7352 firmware | =romepi_1.0.0.d | |
AMD EPYC 7352 | ||
All of | ||
Amd Epyc Server Firmware | =romepi_1.0.0.d | |
AMD EPYC 7402 | ||
All of | ||
AMD EPYC 7402P Firmware | =romepi_1.0.0.d | |
AMD EPYC 7402P | ||
All of | ||
AMD EPYC 7452 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7452 | ||
All of | ||
Amd Epyc Server Firmware | =romepi_1.0.0.d | |
AMD EPYC 7502 | ||
All of | ||
AMD EPYC 7502P Firmware | =romepi_1.0.0.d | |
AMD EPYC 7502P | ||
All of | ||
AMD EPYC 7532 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7532 | ||
All of | ||
AMD EPYC 7542 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7542 | ||
All of | ||
AMD EPYC 7552 Firmware | =romepi_1.0.0.d | |
AMD EPYC Embedded 7552 | ||
All of | ||
AMD EPYC 7642 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7642 Firmware | ||
All of | ||
AMD EPYC 7662 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7662 | ||
All of | ||
AMD EPYC 7702 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7702 | ||
All of | ||
AMD EPYC 7702 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7702p | ||
All of | ||
AMD EPYC 7742 firmware | =romepi_1.0.0.d | |
AMD EPYC 7742 firmware | ||
All of | ||
AMD EPYC 7F32 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7F32 Firmware | ||
All of | ||
AMD EPYC 7F52 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7F52 | ||
All of | ||
AMD EPYC 7F72 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7F72 | ||
All of | ||
AMD EPYC 7H12 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7H12 | ||
All of | ||
AMD EPYC 7251 Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7251 | ||
All of | ||
AMD EPYC 7261 Firmware | =naplespi_1.0.0.h | |
AMD Epyc 7261 | ||
All of | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7281 Firmware | ||
All of | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7301 Firmware | ||
All of | ||
AMD EPYC 7351P Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7351P Firmware | ||
All of | ||
AMD EPYC 7351P Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7351P Firmware | ||
All of | ||
AMD EPYC 7371 Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7371 Firmware | ||
All of | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7401 | ||
All of | ||
AMD EPYC 7401P Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7401P | ||
All of | ||
AMD EPYC 7451 Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7451 Firmware | ||
All of | ||
AMD EPYC 7501 firmware | =naplespi_1.0.0.h | |
AMD EPYC 7501 | ||
All of | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7551 Firmware | ||
All of | ||
AMD EPYC 7551P Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7551P Firmware | ||
All of | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7571 | ||
All of | ||
AMD EPYC 7601 Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7601 Firmware | ||
AMD EPYC 72F3 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 72F3 Firmware | ||
Amd Epyc Server Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7313P | ||
AMD EPYC 7313P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7313P | ||
Amd Epyc Server Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7343 | ||
AMD EPYC 7373X Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7373X | ||
AMD EPYC 73F3 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 73F3 | ||
AMD EPYC 7413 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7413 Firmware | ||
AMD EPYC 7443 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7443 | ||
AMD EPYC 7443P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7443P | ||
Amd Epyc Server Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7453 | ||
AMD EPYC 7473X Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7473X | ||
AMD EPYC 74F3 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 74F3 | ||
AMD EPYC 7513 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7513 | ||
Amd Epyc Server Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7543 Firmware | ||
AMD EPYC 7543P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7543P Firmware | ||
AMD EPYC 7573X Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7573X | ||
AMD EPYC 75F3 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 75F3 | ||
AMD EPYC 7643 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7643 | ||
AMD EPYC 7663 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7663 Firmware | ||
AMD EPYC 7713P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7713 | ||
AMD EPYC 7713P Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7713P Firmware | ||
AMD EPYC 7763 Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7763 Firmware | ||
AMD EPYC 7773X Firmware | =milanpi_1.0.0.5 | |
AMD EPYC 7773X | ||
AMD EPYC 7232p firmware | =romepi_1.0.0.d | |
AMD EPYC 7232p firmware | ||
AMD EPYC 7252 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7252 Firmware | ||
AMD EPYC 7262 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7262 Firmware | ||
AMD EPYC 7272 firmware | =romepi_1.0.0.d | |
AMD EPYC 7272 firmware | ||
AMD EPYC 7282 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7282 | ||
Amd Epyc Server Firmware | =romepi_1.0.0.d | |
AMD EPYC 7302P | ||
AMD EPYC 7302P Firmware | =romepi_1.0.0.d | |
AMD EPYC 7302P | ||
AMD EPYC 7352 firmware | =romepi_1.0.0.d | |
AMD EPYC 7352 | ||
Amd Epyc Server Firmware | =romepi_1.0.0.d | |
AMD EPYC 7402 | ||
AMD EPYC 7402P Firmware | =romepi_1.0.0.d | |
AMD EPYC 7402P | ||
AMD EPYC 7452 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7452 | ||
Amd Epyc Server Firmware | =romepi_1.0.0.d | |
AMD EPYC 7502 | ||
AMD EPYC 7502P Firmware | =romepi_1.0.0.d | |
AMD EPYC 7502P | ||
AMD EPYC 7532 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7532 | ||
AMD EPYC 7542 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7542 | ||
AMD EPYC 7552 Firmware | =romepi_1.0.0.d | |
AMD EPYC Embedded 7552 | ||
AMD EPYC 7642 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7642 Firmware | ||
AMD EPYC 7662 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7662 | ||
AMD EPYC 7702 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7702 | ||
AMD EPYC 7702 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7702p | ||
AMD EPYC 7742 firmware | =romepi_1.0.0.d | |
AMD EPYC 7742 firmware | ||
AMD EPYC 7F32 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7F32 Firmware | ||
AMD EPYC 7F52 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7F52 | ||
AMD EPYC 7F72 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7F72 | ||
AMD EPYC 7H12 Firmware | =romepi_1.0.0.d | |
AMD EPYC 7H12 | ||
AMD EPYC 7251 Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7251 | ||
AMD EPYC 7261 Firmware | =naplespi_1.0.0.h | |
AMD Epyc 7261 | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7281 Firmware | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7301 Firmware | ||
AMD EPYC 7351P Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7351P Firmware | ||
AMD EPYC 7351P Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7351P Firmware | ||
AMD EPYC 7371 Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7371 Firmware | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7401 | ||
AMD EPYC 7401P Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7401P | ||
AMD EPYC 7451 Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7451 Firmware | ||
AMD EPYC 7501 firmware | =naplespi_1.0.0.h | |
AMD EPYC 7501 | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7551 Firmware | ||
AMD EPYC 7551P Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7551P Firmware | ||
Amd Epyc Server Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7571 | ||
AMD EPYC 7601 Firmware | =naplespi_1.0.0.h | |
AMD EPYC 7601 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2023-20520 vulnerability is about improper access control settings in ASP Bootloader that may allow an attacker to corrupt the return address causing a stack-based buffer overrun potentially leading to arbitrary code execution.
The severity level of CVE-2023-20520 is critical with a CVSS score of 9.8.
The affected software by CVE-2023-20520 includes Amd Epyc 72f3, Amd Epyc 7313, Amd Epyc 7343, and more with specific firmware versions.
To fix the CVE-2023-20520 vulnerability, it is recommended to apply the security updates provided by the software vendor.
More information about CVE-2023-20520 can be found at the AMD Product Security Bulletin link: https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3001.