CVE-2023-31339
Severity CVSS v4.0:
Pending analysis
Type:
CWE-20
Input Validation
Publication date:
13/08/2024
Last modified:
27/11/2024
Description
Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.
Impact
Base Score 3.x
4.80
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:amd:trusted_firmware-a:*:*:*:*:*:*:*:* | 2023.2 (excluding) | |
| cpe:2.3:o:arm:trusted_firmware-a:*:*:*:*:*:*:*:* | 2.10.1 (excluding) | |
| cpe:2.3:h:amd:zu11eg:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu15eg:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu17eg:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu19eg:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu1cg:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu1eg:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu21dr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu25dr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu27dr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu28dr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu29dr:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu2cg:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:zu2eg:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



