CVE-2023-20597

Severity CVSS v4.0:
Pending analysis
Type:
CWE-824 Access of Uninitialized Pointer
Publication date:
20/09/2023
Last modified:
27/06/2025

Description

Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amd:ryzen_3_3100_firmware:comboam4pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3100_firmware:comboam4v2pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3100:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3200g_firmware:comboam4pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3200g_firmware:comboam4v2pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3200g:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3200ge_firmware:comboam4pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3200ge_firmware:comboam4v2pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3200ge:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3200u_firmware:comboam4pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3200u_firmware:comboam4v2pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3200u:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3250c_firmware:comboam4pi_1.0.0.9:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3250c_firmware:comboam4v2pi_1.2.0.8:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3250c:-:*:*:*:*:*:*:*