CVE-2023-20521: Medium severity amd epyc server firmware vulnerability
TOCTOU in the ASP Bootloader may allow an attacker with physical access to tamper with SPI ROM records after memory content verification, potentially leading to loss of confidentiality or a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20521?
The severity of CVE-2023-20521 is considered high due to the potential compromise of confidentiality and denial of service.
How do I fix CVE-2023-20521?
To fix CVE-2023-20521, update to the latest firmware version provided by AMD that addresses this vulnerability.
Who is affected by CVE-2023-20521?
CVE-2023-20521 affects specific AMD EPYC processor firmware versions prior to the latest release.
What does CVE-2023-20521 exploit involve?
CVE-2023-20521 involves a time-of-check to time-of-use (TOCTOU) vulnerability that allows an attacker with physical access to manipulate SPI ROM records.
What could happen if CVE-2023-20521 is exploited?
Exploitation of CVE-2023-20521 could lead to unauthorized access to sensitive data or denial of service due to compromised firmware integrity.