CVE-2023-20576: High severity AGESA vulnerability
Published Sep 2, 2026
·Updated
Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
Affected Software
1 affected component
AGESA
Event History
Sep 2, 2026
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of attacker access is required for exploitation?
The CVSS vector indicates local access is required. No privileges or user interaction are required.
2
What security impact is indicated by the CVSS assessment?
The assessment indicates high confidentiality and availability impact, with no integrity impact indicated.