Cyber Resilience

CVE-2022-23815

High

Published: 13 August 2024

Published
13 August 2024
Modified
18 March 2025
KEV Added
Patch
CVSS Score v3.1 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
EPSS Score 0.0008 24.2th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2022-23815 is a high-severity Out-of-bounds Write (CWE-787) vulnerability in Amd Athlon Silver 3050U Firmware. Its CVSS base score is 7.5 (High).

Operationally, ranked at the 24.2th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

Improper bounds checking in APCB firmware may allow an attacker to perform an out of bounds write, corrupting the APCB entry, potentially leading to arbitrary code execution.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

amd
athlon silver 3050u firmware
≤ picassopi-fp5_1.0.0.e
amd
athlon gold 3150u firmware
≤ picassopi-fp5_1.0.0.e
amd
ryzen 7 3780u firmware
≤ picassopi-fp5_1.0.0.e
amd
ryzen 7 3750h firmware
≤ picassopi-fp5_1.0.0.e
amd
ryzen 7 pro 3700u firmware
≤ picassopi-fp5_1.0.0.e
amd
ryzen 7 3700u firmware
≤ picassopi-fp5_1.0.0.e
amd
ryzen 5 3580u firmware
≤ picassopi-fp5_1.0.0.e
amd
ryzen 5 3550h firmware
≤ picassopi-fp5_1.0.0.e
amd
ryzen 5 3500u firmware
≤ picassopi-fp5_1.0.0.e
amd
ryzen 3 3300u firmware
≤ picassopi-fp5_1.0.0.e
+6 more product configuration(s) — see NVD for full list

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-787

Out-of-bounds writes that corrupt control flow or inject shellcode are rendered non-executable by the same memory protections.

References