Cyber Resilience

CVE-2023-20533

Amd Ryzen Threadripper Pro 3995Wx Firmware ≤ chagallwspi-swrx8_1.0.0.5

Published
14 November 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 6.1
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:H
EPSS Score 0.0050 40th percentile
Risk Priority 43 floored blend · peak EPSS

Summary

CVE-2023-20533 is a medium-severity an unspecified weakness vulnerability in Amd Ryzen Threadripper Pro 3995Wx Firmware. Its CVSS base score is 6.1 (Medium).

Operationally, ranked at the 40th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

Insufficient DRAM address validation in System Management Unit (SMU) may allow an attacker to read/write from/to an invalid DRAM address, potentially resulting in denial-of-service.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-20524Same product: Amd Epyc 7232P
CVE-2023-20592Same product: Amd Epyc 7203
CVE-2023-20529Same product: Amd Epyc 7232P
CVE-2023-20528Same product: Amd Epyc 7232P
CVE-2023-20532Same product: Amd Epyc 7232P
CVE-2023-20525Same product: Amd Epyc 7232P
CVE-2023-20531Same product: Amd Epyc 7232P
CVE-2023-20523Same product: Amd Epyc 7232P
CVE-2023-20526Same product: Amd Epyc 7203
CVE-2023-20520Same product: Amd Epyc 7232P

Affected Assets

amd
epyc 7232p firmware
≤ romepi_1.0.0.d
amd
epyc 7252 firmware
≤ romepi_1.0.0.d
amd
epyc 7262 firmware
≤ romepi_1.0.0.d
amd
epyc 7272 firmware
≤ romepi_1.0.0.d
amd
epyc 7282 firmware
≤ romepi_1.0.0.d
amd
epyc 7302 firmware
≤ romepi_1.0.0.d
amd
epyc 7302p firmware
≤ romepi_1.0.0.d
amd
epyc 7352 firmware
≤ romepi_1.0.0.d
amd
epyc 7402 firmware
≤ romepi_1.0.0.d
amd
epyc 7402p firmware
≤ romepi_1.0.0.d
+75 more product configuration(s) — see NVD for full list

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References