First published: Tue Nov 14 2023(Updated: )
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Amd Epyc Server Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7001 | ||
All of | ||
AMD EPYC 7251 Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7251 | ||
All of | ||
AMD EPYC 7261 Firmware | <naplespi_1.0.0.h | |
AMD Epyc 7261 | ||
All of | ||
Amd Epyc Server Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7281 Firmware | ||
All of | ||
Amd Epyc Server Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7301 Firmware | ||
All of | ||
AMD EPYC 7351P Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7351P Firmware | ||
All of | ||
AMD EPYC 7351P Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7351P Firmware | ||
All of | ||
AMD EPYC 7371 Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7371 Firmware | ||
All of | ||
Amd Epyc Server Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7401 | ||
All of | ||
AMD EPYC 7401P Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7401P | ||
All of | ||
AMD EPYC 7451 Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7451 Firmware | ||
All of | ||
AMD EPYC 7501 firmware | <naplespi_1.0.0.h | |
AMD EPYC 7501 | ||
All of | ||
Amd Epyc Server Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7551 Firmware | ||
All of | ||
AMD EPYC 7551P Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7551P Firmware | ||
All of | ||
AMD EPYC 7601 Firmware | <naplespi_1.0.0.h | |
AMD EPYC 7601 Firmware | ||
All of | ||
AMD EPYC 7232p firmware | <romepi_1.0.0.d | |
AMD EPYC 7232p firmware | ||
All of | ||
AMD EPYC 7252 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7252 Firmware | ||
All of | ||
AMD EPYC 7262 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7262 Firmware | ||
All of | ||
AMD EPYC 7272 firmware | <romepi_1.0.0.d | |
AMD EPYC 7272 firmware | ||
All of | ||
AMD EPYC 7282 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7282 | ||
All of | ||
Amd Epyc Server Firmware | <romepi_1.0.0.d | |
AMD EPYC 7302P | ||
All of | ||
AMD EPYC 7302P Firmware | <romepi_1.0.0.d | |
AMD EPYC 7302P | ||
All of | ||
AMD EPYC 7352 firmware | <romepi_1.0.0.d | |
AMD EPYC 7352 | ||
All of | ||
Amd Epyc Server Firmware | <romepi_1.0.0.d | |
AMD EPYC 7402 | ||
All of | ||
AMD EPYC 7402P Firmware | <romepi_1.0.0.d | |
AMD EPYC 7402P | ||
All of | ||
AMD EPYC 7452 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7452 | ||
All of | ||
Amd Epyc Server Firmware | <romepi_1.0.0.d | |
AMD EPYC 7502 | ||
All of | ||
AMD EPYC 7502P Firmware | <romepi_1.0.0.d | |
AMD EPYC 7502P | ||
All of | ||
AMD EPYC 7532 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7532 | ||
All of | ||
AMD EPYC 7542 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7542 | ||
All of | ||
AMD EPYC 7552 Firmware | <romepi_1.0.0.d | |
AMD EPYC Embedded 7552 | ||
All of | ||
AMD EPYC 7642 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7642 Firmware | ||
All of | ||
AMD EPYC 7662 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7662 | ||
All of | ||
AMD EPYC 7702 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7702 | ||
All of | ||
AMD EPYC 7702 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7702p | ||
All of | ||
AMD EPYC 7742 firmware | <romepi_1.0.0.d | |
AMD EPYC 7742 firmware | ||
All of | ||
AMD EPYC 7F32 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7F32 Firmware | ||
All of | ||
AMD EPYC 7F52 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7F52 | ||
All of | ||
AMD EPYC 7F72 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7F72 | ||
All of | ||
AMD EPYC 7H12 Firmware | <romepi_1.0.0.d | |
AMD EPYC 7H12 | ||
All of | ||
AMD EPYC 7763 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7763 Firmware | ||
All of | ||
AMD EPYC 7713P Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7713P Firmware | ||
All of | ||
AMD EPYC 7713P Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7713 | ||
All of | ||
amd epyc 7663p firmware | <milanpi_1.0.0.7 | |
amd epyc 7663p | ||
All of | ||
AMD EPYC 7663 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7663 Firmware | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
amd epyc 7643p | ||
All of | ||
AMD EPYC 7773X Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7773X | ||
All of | ||
AMD EPYC 7643 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7643 | ||
All of | ||
AMD EPYC 7573X Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7573X | ||
All of | ||
AMD EPYC 75F3 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 75F3 | ||
All of | ||
AMD EPYC 7543P Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7543P Firmware | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7543 Firmware | ||
All of | ||
AMD EPYC 7513 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7513 | ||
All of | ||
AMD EPYC 7473X Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7473X | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7453 | ||
All of | ||
AMD EPYC 74F3 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 74F3 | ||
All of | ||
AMD EPYC 7443P Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7443P | ||
All of | ||
AMD EPYC 7443 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7443 | ||
All of | ||
AMD EPYC 7413 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7413 Firmware | ||
All of | ||
AMD EPYC 7373X Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7373X | ||
All of | ||
AMD EPYC 73F3 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 73F3 | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7343 | ||
All of | ||
AMD EPYC 7313P Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7313P | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 7313P | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
amd epyc 7303p | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
amd epyc 7303 | ||
All of | ||
AMD EPYC 72F3 Firmware | <milanpi_1.0.0.7 | |
AMD EPYC 72F3 Firmware | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
amd epyc 7203p | ||
All of | ||
Amd Epyc Server Firmware | <milanpi_1.0.0.7 | |
amd epyc 7203 | ||
All of | ||
AMD Athlon Pro 300GE Firmware | ||
AMD Athlon Pro 300GE | ||
All of | ||
AMD Athlon Gold Pro 3150GE Firmware | ||
AMD Athlon Gold Pro 3150GE Firmware | ||
All of | ||
AMD Athlon Gold Pro 3150G Firmware | ||
AMD Athlon Gold Pro 3150G Firmware | ||
All of | ||
AMD Athlon Gold Pro 3150G Firmware | ||
AMD Athlon Gold Pro 3150G Firmware | ||
All of | ||
AMD Ryzen Threadripper 2990WX | <summitpi-sp3r2_1.1.0.6 | |
AMD Ryzen Threadripper 2990WX | ||
All of | ||
AMD Ryzen Threadripper 2970WX Firmware | <summitpi-sp3r2_1.1.0.6 | |
AMD Ryzen Threadripper 2970WX Firmware | ||
All of | ||
AMD Ryzen Threadripper 2950X Firmware | <summitpi-sp3r2_1.1.0.6 | |
AMD Ryzen Threadripper 2950X Firmware | ||
All of | ||
AMD Ryzen Threadripper 2920X Firmware | <summitpi-sp3r2_1.1.0.6 | |
AMD Ryzen Threadripper 2920X Firmware | ||
All of | ||
amd ryzen 7 3780u firmware | <picassopi-fp5_1.0.0.e | |
amd ryzen 7 3780u | ||
All of | ||
AMD Ryzen 7 3750H Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 7 3750H | ||
All of | ||
AMD Ryzen 7 3700C Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 7 3700C Firmware | ||
All of | ||
AMD Ryzen 7 3700U Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 7 3700U | ||
All of | ||
amd ryzen 5 3580u firmware | <picassopi-fp5_1.0.0.e | |
amd ryzen 5 3580u | ||
All of | ||
AMD Ryzen 5 3550H Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 5 3550H Firmware | ||
All of | ||
AMD Ryzen 5 3500C Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 5 3500C Firmware | ||
All of | ||
AMD Ryzen 5 3500U Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 5 3500U | ||
All of | ||
AMD Ryzen 5 3450U Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 5 3450U | ||
All of | ||
amd ryzen 3 3350u firmware | <picassopi-fp5_1.0.0.e | |
amd ryzen 3 3350u | ||
All of | ||
AMD Ryzen 3 Pro 3300U Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 3 Pro 3300U | ||
All of | ||
AMD Ryzen 3 3250U Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 3 3250U Firmware | ||
All of | ||
AMD Ryzen 3 3250C Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 3 3250C | ||
All of | ||
AMD Ryzen 3 3200U Firmware | <picassopi-fp5_1.0.0.e | |
AMD Ryzen 3 3200U Firmware | ||
All of | ||
AMD 3015e firmware | <pollockpi-ft5_1.0.0.4 | |
AMD 3015e firmware | ||
All of | ||
AMD AMD 3015ce firmware | <pollockpi-ft5_1.0.0.4 | |
AMD AMD 3015ce firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-20521 is considered high due to the potential compromise of confidentiality and denial of service.
To fix CVE-2023-20521, update to the latest firmware version provided by AMD that addresses this vulnerability.
CVE-2023-20521 affects specific AMD EPYC processor firmware versions prior to the latest release.
CVE-2023-20521 involves a time-of-check to time-of-use (TOCTOU) vulnerability that allows an attacker with physical access to manipulate SPI ROM records.
Exploitation of CVE-2023-20521 could lead to unauthorized access to sensitive data or denial of service due to compromised firmware integrity.