CWE
20
Advisory Published
Updated

CVE-2023-20596: Input Validation

First published: Tue Nov 14 2023(Updated: )

Improper input validation in the SMM Supervisor may allow an attacker with a compromised SMI handler to gain Ring0 access potentially leading to arbitrary code execution.

Credit: psirt@amd.com

Affected SoftwareAffected VersionHow to fix
AMD Ryzen 7 5700G Firmware<comboam4v2_1.2.0.b
AMD Ryzen 7 5700G Firmware
AMD Ryzen 7 5700GE Firmware<comboam4v2_1.2.0.b
AMD Ryzen 7 5700GE Firmware
AMD Ryzen 5 5600G<comboam4v2_1.2.0.b
AMD Ryzen 5 5600GT Firmware
AMD Ryzen 5 5600GE Firmware<comboam4v2_1.2.0.b
AMD Ryzen 5 5600GE Firmware
AMD Ryzen 3 5300G Firmware<comboam4v2_1.2.0.b
AMD Ryzen 3 5300G Firmware
AMD Ryzen 5300GE Firmware<comboam4v2_1.2.0.b
AMD Ryzen 3 5300GE Firmware
AMD Ryzen 9 7950X3D Firmware<comboam5pi_1.0.8.0
AMD Ryzen 9 7950X3D
AMD Ryzen 9 7950X<comboam5pi_1.0.8.0
AMD Ryzen 9 7950X
AMD Ryzen 9 7900X3D firmware<comboam5pi_1.0.8.0
AMD Ryzen 9 7900X3D firmware
AMD Ryzen 9 7900 Firmware<comboam5pi_1.0.8.0
AMD Ryzen 9 7900
AMD Ryzen 9 7900X Firmware<comboam5pi_1.0.8.0
AMD Ryzen 9 7900X Firmware
AMD Ryzen 9 Pro 7945HS Firmware<comboam5pi_1.0.8.0
AMD Ryzen Pro 7945
AMD Ryzen 7 7800X3D Firmware<comboam5pi_1.0.8.0
AMD Ryzen 7 7800X3D
AMD Ryzen 7 7700X Firmware<comboam5pi_1.0.8.0
AMD Ryzen 7 7700X
AMD Ryzen 7 7700 Firmware<comboam5pi_1.0.8.0
AMD Ryzen 7 7700
AMD Ryzen Pro 7745 Firmware<comboam5pi_1.0.8.0
AMD Ryzen 7 Pro 7745 Firmware
AMD Ryzen 5 7600X Firmware<comboam5pi_1.0.8.0
AMD Ryzen 5 7600X Firmware
AMD Ryzen 5 7600 Firmware<comboam5pi_1.0.8.0
AMD Ryzen 5 7600
AMD Ryzen 5 Pro 7645 Firmware<comboam5pi_1.0.8.0
AMD Ryzen Pro 7645
AMD Ryzen 5 7500F Firmware<comboam5pi_1.0.8.0
AMD Ryzen 5 7500F Firmware
AMD Ryzen 9 5980HX<cezannepi-fp6_1.0.0.fa
AMD Ryzen 9 5980HX
AMD Ryzen 9 5980HS Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 9 5980HS Firmware
AMD Ryzen 9 5900HX Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 9 5900HX Firmware
AMD Ryzen 9 5900HS Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 9 5900HS Firmware
AMD Ryzen 7 5800H Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 7 5800H Firmware
AMD Ryzen 7 5800HS Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 7 5800HS Firmware
AMD Ryzen 7 5825U Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 7 5825U Firmware
AMD Ryzen 7 5800U Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 7 5800U Firmware
AMD Ryzen 5 5600H Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 5 5600H Firmware
AMD Ryzen 5 5600HS Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 5 5600HS Firmware
AMD Ryzen 5 5625U Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 5 5625U Firmware
AMD Ryzen 5 5600U Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 5 5600U Firmware
AMD Ryzen 5 5560U Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 5 5560U Firmware
AMD Ryzen 5 5500H Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 5 5500H Firmware
AMD Ryzen 3 5425U<cezannepi-fp6_1.0.0.fa
AMD Ryzen 3 5425U Firmware
AMD Ryzen 3 5400U Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 3 5400U Firmware
AMD Ryzen 3 5125C Firmware<cezannepi-fp6_1.0.0.fa
AMD Ryzen 3 5125C Firmware
AMD Ryzen 9 6980HX<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 9 6980HX firmware
AMD Ryzen 6980HS Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 9 6980HS Firmware
AMD Ryzen 9 6900HX Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 9 6900HX Firmware
AMD Ryzen 6900HS Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 9 6900HS Firmware
AMD Ryzen 7 6800H Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 7 6800H Firmware
AMD Ryzen 7 6800H Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 7 6800HS firmware
AMD Ryzen 7 6800U Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 7 6800U Firmware
AMD Ryzen 5 6600H firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 5 6600H firmware
AMD Ryzen 6600HS<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 5 6600HS Firmware
AMD Ryzen 6600U Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 5 6600U Firmware
AMD Ryzen 7 7735HS Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 7 7735HS Firmware
AMD Ryzen 7 7736U Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 7 7736U
AMD Ryzen 7 7735U Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 7 7735U Firmware
AMD Ryzen 5 7535HS Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 5 7535HS Firmware
AMD Ryzen 5 7535U firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 5 7535U firmware
AMD Ryzen 3 7335U Firmware<rembrandtpi-fp7_1.0.0.9b
AMD Ryzen 3 7335U Firmware
AMD Ryzen 9 Pro 7940HS Firmware<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 9 Pro 7940HS
AMD Ryzen 9 7940H Firmware<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 9 7940H
AMD Ryzen 7 Pro 7840HS Firmware<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 7 Pro 7840HS
AMD Ryzen 7 Pro 7840H<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 7 Pro 7840H
AMD Ryzen 7 Pro 7840U<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 7 Pro 7840U
AMD Ryzen 5 Pro 7640H Firmware<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 5 Pro 7640HS Firmware
AMD Ryzen 5 Pro 7640H Firmware<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 5 PRO 7640H
AMD Ryzen 5 7640U Firmware<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 5 Pro 7640U Firmware
AMD Ryzen 5 PRO 7545U<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 5 PRO 7545U
AMD Ryzen 5 Pro 7540U<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 5 Pro 7540U Firmware
AMD Ryzen 3 Pro 7440U<phoenixpi-fp8-fp7_1.0.0.2
AMD Ryzen 3 7440U Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2023-20596?

    CVE-2023-20596 is considered a critical vulnerability allowing potential arbitrary code execution due to improper input validation.

  • How do I fix CVE-2023-20596?

    To fix CVE-2023-20596, update the affected AMD firmware to the latest version that patches the vulnerability.

  • Which AMD products are affected by CVE-2023-20596?

    Affected products include various AMD Ryzen firmware versions up to comboam4v2_1.2.0.b and comboam5pi_1.0.8.0.

  • What type of attack is associated with CVE-2023-20596?

    CVE-2023-20596 is associated with attacks that exploit improper input validation in the SMM Supervisor to gain Ring0 access.

  • Is CVE-2023-20596 a hardware or software vulnerability?

    CVE-2023-20596 is primarily a firmware vulnerability affecting the software layer that interacts with AMD hardware.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203