2.3

CVSS3.1

CVE-2023-31304 -

Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) ย  ย  to modify the PCIeยฎ lane count and speed, potentially leading to a loss of availability.

๐Ÿ“… Published: Aug. 13, 2024, 4:53 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.9

CVSS3.1

CVE-2023-31305 -

Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure.

๐Ÿ“… Published: Aug. 13, 2024, 4:53 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2023-20591 -

Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.

๐Ÿ“… Published: Aug. 13, 2024, 4:53 p.m. ๐Ÿ”„ Last Modified: March 13, 2025, 5:15 p.m.

7.5

CVSS3.1

CVE-2023-20578 -

A TOCTOU (Time-Of-Check-Time-Of-Use) in SMM may allow an attacker with ring0 privileges and access to the BIOS menu or UEFI shell to modify the communications bufferย potentially resulting in arbitrary code execution.

๐Ÿ“… Published: Aug. 13, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: March 18, 2025, 8:15 p.m.

1.9

CVSS3.1

CVE-2023-20518 -

Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.

๐Ÿ“… Published: Aug. 13, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

3.3

CVSS3.1

CVE-2023-20513 -

An insufficient bounds check in PMFW (Power Management Firmware) may allow an attacker to utilize a malicious VF (virtualization function) to send a malformed message, potentially resulting in a denial of service.

๐Ÿ“… Published: Aug. 13, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

1.9

CVSS3.1

CVE-2023-20512 -

A hardcoded AES key in PMFW may result in a privileged attacker gaining access to the key, potentially resulting in internal debug information leakage.

๐Ÿ“… Published: Aug. 13, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.7

CVSS3.1

CVE-2023-20510 -

An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to SRAM, potentially resulting in data corruption or denial of service.

๐Ÿ“… Published: Aug. 13, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: Dec. 12, 2024, 8:28 p.m.

5.2

CVSS3.1

CVE-2023-20509 -

An insufficient DRAM address validation in PMFW may allow a privileged attacker to perform a DMA read from an invalid DRAM address to SRAM, potentially resulting in loss of data integrity.

๐Ÿ“… Published: Aug. 13, 2024, 4:52 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.

7

CVSS3.1

CVE-2022-23817 -

Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space, potentially leading to privilege escalation.

๐Ÿ“… Published: Aug. 13, 2024, 4:51 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8877 of 34,919
ยซ previous page ยป next page
Filters