CVE-2023-20591: Critical severity amd epyc 8024pn firmware vulnerability
Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-20591?
CVE-2023-20591 has a high severity rating due to the potential for an attacker to read or modify hypervisor memory.
How do I fix CVE-2023-20591?
To fix CVE-2023-20591, update the affected firmware to the latest version beyond genoapi_1.0.0.8 or milanpi_1.0.0.b.
Which systems are affected by CVE-2023-20591?
CVE-2023-20591 affects several models of AMD EPYC processors with specific firmware versions including genoapi_1.0.0.8 and milanpi_1.0.0.b.
What can an attacker achieve with CVE-2023-20591?
An attacker can potentially read or modify hypervisor memory, leading to a loss of confidentiality, integrity, and availability.
Is CVE-2023-20591 specific to AMD EPYC processors?
Yes, CVE-2023-20591 specifically impacts AMD EPYC processors and their related firmware.