CVE-2023-20570
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
13/02/2024
Last modified:
22/03/2025
Description
Insufficient verification of data authenticity in<br />
the configuration state machine may allow a local attacker to potentially load<br />
arbitrary bitstreams.<br />
<br />
<br />
<br />
<br />
<br />
Impact
Base Score 3.x
3.30
Severity 3.x
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:amd:alveo_u50_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:alveo_u50:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:alveo_u200_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:alveo_u200:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:alveo_u250_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:alveo_u250:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:alveo_u280_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:alveo_u280:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:kintex_ultrascale\+_ku3p_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:kintex_ultrascale\+_ku3p:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:kintex_ultrascale\+_ku5p_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:kintex_ultrascale\+_ku5p:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:kintex_ultrascale\+_ku9p_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:kintex_ultrascale\+_ku9p:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:kintex_ultrascale\+_ku11p_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



