CVE-2023-20526: Input Validation

Published Nov 14, 2023
·
Updated

Insufficient input validation in the ASP Bootloader may enable a privileged attacker with physical access to expose the contents of ASP memory potentially leading to a loss of confidentiality.

Affected Software

146 affected components
All of the following
AMD Epyc 7001 Firmware<naplespi_1.0.0.h
AMD Epyc 7001
All of the following
AMD Epyc 7251 Firmware<naplespi_1.0.0.h
AMD Epyc 7251
All of the following
AMD Epyc 7261 Firmware<naplespi_1.0.0.h
AMD Epyc 7261
All of the following
AMD Epyc 7281 Firmware<naplespi_1.0.0.h
AMD Epyc 7281
All of the following
AMD Epyc 7301 Firmware<naplespi_1.0.0.h
AMD Epyc 7301
All of the following
AMD Epyc 7351 Firmware<naplespi_1.0.0.h
AMD Epyc 7351
All of the following
AMD Epyc 7351p Firmware<naplespi_1.0.0.h
AMD Epyc 7351p
All of the following
AMD Epyc 7371 Firmware<naplespi_1.0.0.h
AMD Epyc 7371
All of the following
AMD Epyc 7401 Firmware<naplespi_1.0.0.h
AMD Epyc 7401
All of the following
AMD Epyc 7401p Firmware<naplespi_1.0.0.h
AMD Epyc 7401p
All of the following
AMD Epyc 7451 Firmware<naplespi_1.0.0.h
AMD Epyc 7451
All of the following
AMD Epyc 7501 Firmware<naplespi_1.0.0.h
AMD Epyc 7501
All of the following
AMD Epyc 7551 Firmware<naplespi_1.0.0.h
AMD Epyc 7551
All of the following
AMD Epyc 7551p Firmware<naplespi_1.0.0.h
AMD Epyc 7551p
All of the following
AMD Epyc 7601 Firmware<naplespi_1.0.0.h
AMD Epyc 7601
All of the following
AMD Epyc 7232p Firmware<romepi_1.0.0.d
AMD Epyc 7232p
All of the following
AMD Epyc 7252 Firmware<romepi_1.0.0.d
AMD Epyc 7252
All of the following
AMD Epyc 7262 Firmware<romepi_1.0.0.d
AMD Epyc 7262
All of the following
AMD Epyc 7272 Firmware<romepi_1.0.0.d
AMD Epyc 7272
All of the following
AMD Epyc 7282 Firmware<romepi_1.0.0.d
AMD Epyc 7282
All of the following
AMD Epyc 7302 Firmware<romepi_1.0.0.d
AMD Epyc 7302
All of the following
AMD Epyc 7302p Firmware<romepi_1.0.0.d
AMD Epyc 7302p
All of the following
AMD Epyc 7352 Firmware<romepi_1.0.0.d
AMD Epyc 7352
All of the following
AMD Epyc 7402 Firmware<romepi_1.0.0.d
AMD Epyc 7402
All of the following
AMD Epyc 7402p Firmware<romepi_1.0.0.d
AMD Epyc 7402p
All of the following
AMD Epyc 7452 Firmware<romepi_1.0.0.d
AMD Epyc 7452
All of the following
AMD Epyc 7502 Firmware<romepi_1.0.0.d
AMD Epyc 7502
All of the following
AMD Epyc 7502p Firmware<romepi_1.0.0.d
AMD Epyc 7502p
All of the following
AMD Epyc 7532 Firmware<romepi_1.0.0.d
AMD Epyc 7532
All of the following
AMD Epyc 7542 Firmware<romepi_1.0.0.d
AMD Epyc 7542
All of the following
AMD Epyc 7552 Firmware<romepi_1.0.0.d
AMD Epyc 7552
All of the following
AMD Epyc 7642 Firmware<romepi_1.0.0.d
AMD Epyc 7642
All of the following
AMD Epyc 7662 Firmware<romepi_1.0.0.d
AMD Epyc 7662
All of the following
AMD Epyc 7702 Firmware<romepi_1.0.0.d
AMD Epyc 7702
All of the following
AMD Epyc 7702p Firmware<romepi_1.0.0.d
AMD Epyc 7702p
All of the following
AMD Epyc 7742 Firmware<romepi_1.0.0.d
AMD Epyc 7742
All of the following
AMD Epyc 7f32 Firmware<romepi_1.0.0.d
AMD Epyc 7f32
All of the following
AMD Epyc 7f52 Firmware<romepi_1.0.0.d
AMD Epyc 7f52
All of the following
AMD Epyc 7f72 Firmware<romepi_1.0.0.d
AMD Epyc 7f72
All of the following
AMD Epyc 7h12 Firmware<romepi_1.0.0.d
AMD Epyc 7h12
All of the following
AMD Epyc 7763 Firmware<milanpi_1.0.0.5
AMD Epyc 7763
All of the following
AMD Epyc 7713p Firmware<milanpi_1.0.0.5
AMD Epyc 7713p
All of the following
AMD Epyc 7713 Firmware<milanpi_1.0.0.5
AMD Epyc 7713
All of the following
AMD Epyc 7663p Firmware<milanpi_1.0.0.5
AMD Epyc 7663p
All of the following
AMD Epyc 7663 Firmware<milanpi_1.0.0.5
AMD Epyc 7663
All of the following
AMD Epyc 7643p Firmware<milanpi_1.0.0.5
AMD Epyc 7643p
All of the following
AMD Epyc 7773x Firmware<milanpi_1.0.0.5
AMD Epyc 7773x
All of the following
AMD Epyc 7643 Firmware<milanpi_1.0.0.5
AMD Epyc 7643
All of the following
AMD Epyc 7573x Firmware<milanpi_1.0.0.5
AMD Epyc 7573x
All of the following
AMD Epyc 75f3 Firmware<milanpi_1.0.0.5
AMD Epyc 75f3
All of the following
AMD Epyc 7543p Firmware<milanpi_1.0.0.5
AMD Epyc 7543p
All of the following
AMD Epyc 7543 Firmware<milanpi_1.0.0.5
AMD Epyc 7543
All of the following
AMD Epyc 7513 Firmware<milanpi_1.0.0.5
AMD Epyc 7513
All of the following
AMD Epyc 7473x Firmware<milanpi_1.0.0.5
AMD Epyc 7473x
All of the following
AMD Epyc 7453 Firmware<milanpi_1.0.0.5
AMD Epyc 7453
All of the following
AMD Epyc 74f3 Firmware<milanpi_1.0.0.5
AMD Epyc 74f3
All of the following
AMD Epyc 7443p Firmware<milanpi_1.0.0.5
AMD Epyc 7443p
All of the following
AMD Epyc 7443 Firmware<milanpi_1.0.0.5
AMD Epyc 7443
All of the following
AMD Epyc 7413 Firmware<milanpi_1.0.0.5
AMD Epyc 7413
All of the following
AMD Epyc 7373x Firmware<milanpi_1.0.0.5
AMD Epyc 7373x
All of the following
AMD Epyc 73f3 Firmware<milanpi_1.0.0.5
AMD Epyc 73f3
All of the following
AMD Epyc 7343 Firmware<milanpi_1.0.0.5
AMD Epyc 7343
All of the following
AMD Epyc 7313p Firmware<milanpi_1.0.0.5
AMD Epyc 7313p
All of the following
AMD Epyc 7313 Firmware<milanpi_1.0.0.5
AMD Epyc 7313
All of the following
AMD Epyc 7303p Firmware<milanpi_1.0.0.5
AMD Epyc 7303p
All of the following
AMD Epyc 7303 Firmware<milanpi_1.0.0.5
AMD Epyc 7303
All of the following
AMD Epyc 72f3 Firmware<milanpi_1.0.0.5
AMD Epyc 72f3
All of the following
AMD Epyc 7203p Firmware<milanpi_1.0.0.5
AMD Epyc 7203p
All of the following
AMD Epyc 7203 Firmware<milanpi_1.0.0.5
AMD Epyc 7203
All of the following
AMD Ryzen Threadripper 2990wx Firmware<summitpi-sp3r2_1.1.0.7
AMD Ryzen Threadripper 2990wx
All of the following
AMD Ryzen Threadripper 2970wx Firmware<summitpi-sp3r2_1.1.0.7
AMD Ryzen Threadripper 2970wx
All of the following
AMD Ryzen Threadripper 2950x Firmware<summitpi-sp3r2_1.1.0.7
AMD Ryzen Threadripper 2950x
All of the following
AMD Ryzen Threadripper 2920x Firmware<summitpi-sp3r2_1.1.0.7
AMD Ryzen Threadripper 2920x

Event History

Nov 14, 2023
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
DescriptionSeverity
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-20526?

CVE-2023-20526 is classified as a potentially high severity vulnerability due to the risk of unauthorized memory access by a privileged attacker.

2

How do I fix CVE-2023-20526?

To remediate CVE-2023-20526, users should apply the latest firmware updates provided by AMD for affected AMD EPYC and Ryzen Threadripper models.

3

Who is affected by CVE-2023-20526?

CVE-2023-20526 affects various AMD EPYC 7001 series processors and Ryzen Threadripper models with specific firmware versions.

4

What kind of attack does CVE-2023-20526 enable?

CVE-2023-20526 enables a physical attacker with privileged access to potentially expose sensitive information from ASP memory.

5

Is there a workaround for CVE-2023-20526?

Currently, there are no known workarounds for CVE-2023-20526 other than applying firmware updates.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203