Back to overview

CVE-2023-20572

MEDIUM
5.6
CVSS 4.0
Description
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary message, potentially leading to a loss of data integrity.

Metadata

CVE ID
CVE-2023-20572
State
PUBLISHED
Assigner
AMD
Reserved
2022-10-27 18:53 UTC
Published
2026-06-26 15:53 UTC
Last updated
2026-06-26 15:59 UTC
Primary CWE
CWE-208
CWE-208 Observable timing discrepancy
Vendor / Product
AMD / AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics
Sources
cve.org  ·  NVD

Severity & Metrics

5.6 MEDIUM CVSS 4.0
CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
SSVC — CISA Coordinator
Exploitation
none
Automatable
no
Tech. Impact
partial
Affected products (19)
VendorProductPlatformVersions
AMD AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics ComboAM4v2PI 1.2.0.CA
AMD AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics Picasso-FP5 1.0.1.1
AMD AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics Pollock-FT5 1.0.0.7
AMD AMD Ryzen™ 3000 Series Desktop Processors ComboAM4v2PI 1.2.0.CA, ComboAM4PI 1.0.0.F
AMD AMD Ryzen™ 4000 Series Desktop Processors ComboAM4v2PI 1.2.0.CA
AMD AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics Renoir-FP6 1.0.0.D
AMD AMD Ryzen™ 5000 Series Desktop Processors ComboAM4v2PI 1.2.0.CA
AMD AMD Ryzen™ 5000 Series Desktop Processors ComboAM4v2PI 1.2.0.CA
AMD AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics Cezanne-FP6 1.0.1.0
AMD AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics Rembrandt-FP7 1.0.0.A
AMD AMD Ryzen™ 7000 Series Desktop Processors ComboAM5 1.0.0.7a
AMD AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics MendocinoPI-FT6 1.0.0.6
AMD AMD Ryzen™ 7030 Series Mobile processors with Radeon™ Graphics Cezanne-FP6 1.0.1.0
AMD AMD Ryzen™ 8000 Series Desktop Processors ComboAM5 1.0.0.7a
AMD AMD Ryzen™ Threadripper™ 3000 Series Processors CastlePeakPI-SP3r3 1.0.0.C
AMD AMD Ryzen™ Threadripper™ 7000 Processors StormPeakPI-SP6 1.1.0.0c
AMD AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors CastlePeakWSPI-sWRX8 1.0.0.E
AMD AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors ChagallWSPI-sWRX8 1.0.0.9
AMD AMD Ryzen™ Threadripper™ PRO 7000WX-Series Processors StormPeakPI-SP6 1.0.0.1e
Weakness (CWE)
CWESourceDescription
CWE-208 cna CWE-208 Observable timing discrepancy
CVSS scores (1)
ScoreSeverityVersionSourceVector
5.6 MEDIUM 4.0 cna CVSS:4.0/AV:L/AC:H/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Back to overview