CVE-2022-23820

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
14/11/2023
Last modified:
18/06/2024

Description

Failure to validate the AMD SMM communication buffer<br /> may allow an attacker to corrupt the SMRAM potentially leading to arbitrary<br /> code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amd:ryzen_9_3900_firmware:comboam4_pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_9_3900_firmware:comboam4_v2_pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_9_3900:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_9_3900x_firmware:comboam4_pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_9_3900x_firmware:comboam4_v2_pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_9_3900x:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_9_3900xt_firmware:comboam4_pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_9_3900xt_firmware:comboam4_v2_pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_9_3900xt:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_9_3950x_firmware:comboam4_pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_9_3950x_firmware:comboam4_v2_pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_9_3950x:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_7_3700x_firmware:comboam4_pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_7_3700x_firmware:comboam4_v2_pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_7_3700x:-:*:*:*:*:*:*:*