CVE-2023-20578: High severity amd epyc 8024pn firmware vulnerability
A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications buffer potentially resulting in arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20578?
CVE-2023-20578 has a severity rating of critical due to its potential for arbitrary code execution by an attacker with ring0 privileges.
How do I fix CVE-2023-20578?
To fix CVE-2023-20578, you should update your AMD Epyc firmware to a version that is not affected, specifically above genoapi_1.0.0.2 for designated models.
Which devices are affected by CVE-2023-20578?
CVE-2023-20578 affects various AMD Epyc firmware versions prior to genoapi_1.0.0.2 on multiple Amd Epyc models.
What is a TOCTOU vulnerability in the context of CVE-2023-20578?
A TOCTOU vulnerability, as seen in CVE-2023-20578, refers to the potential for an attacker to exploit a race condition between checking and using a resource.
Is CVE-2023-20578 currently being exploited in the wild?
As of now, there are no confirmed reports of CVE-2023-20578 being actively exploited in the wild.