CVE-2023-31347: Medium severity amd epyc 7773x firmware vulnerability
Due to a code bug in SecureTSC, SEV firmware may allow an attacker with high privileges to cause a guest to observe an incorrect TSC when Secure TSC is enabled potentially resulting in a loss of guest integrity.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-31347?
The severity of CVE-2023-31347 is categorized as high due to the potential for an attacker to compromise guest integrity.
How do I fix CVE-2023-31347?
To fix CVE-2023-31347, it is recommended to update the affected AMD EPYC firmware to a version beyond milanpi_1.0.0.c.
Which software is affected by CVE-2023-31347?
CVE-2023-31347 affects multiple AMD EPYC firmware versions, including 7773x, 7763, 7713, and others up to milanpi_1.0.0.c.
Who is vulnerable to CVE-2023-31347?
Organizations using AMD EPYC processors with Secure TSC enabled on firmware versions up to milanpi_1.0.0.c are vulnerable to CVE-2023-31347.
What are the potential impacts of CVE-2023-31347?
The potential impact of CVE-2023-31347 includes the loss of guest integrity due to incorrect TSC observations by the attacker.