CVE-2023-20519
Estado: ModificadaBaja (3.3)—
A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Puntuación base: 3.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-416
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-20519",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-20519",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-08-30T18:03:44.986937Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 3.3,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "psirt@amd.com",
"affectedData": [
{
"vendor": "AMD",
"product": "3rd Gen AMD EPYC™ Processors",
"versions": [
{
"status": "affected",
"version": "various "
}
],
"platforms": [
"x86"
],
"packageName": "PI",
"defaultStatus": "unaffected"
},
{
"vendor": " AMD",
"product": "4th Gen AMD EPYC™ Processors ",
"versions": [
{
"status": "affected",
"version": "various "
}
],
"platforms": [
"x86"
],
"packageName": "PI",
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-11-14T19:15:15.533",
"references": [
{
"url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002",
"tags": [
"Vendor Advisory"
],
"source": "psirt@amd.com"
},
{
"url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-416"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A Use-After-Free vulnerability in the management of an SNP guest context page may allow a malicious hypervisor to masquerade as the guest's migration agent resulting in a potential loss of guest integrity.\n\n\n\n\n\n\n\n\n\n\n\n\n"
},
{
"lang": "es",
"value": "Una vulnerabilidad Use-After-Free en la administración de una página contextual de invitado SNP puede permitir que un hipervisor malicioso se haga pasar por el agente de migración del invitado, lo que resulta en una posible pérdida de integridad del invitado."
}
],
"lastModified": "2026-06-17T05:30:14.817",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:amd:milanpi_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D04D59C4-B1F2-477B-A1B6-ADCA15925FC3",
"versionEndExcluding": "1.0.0.a"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:amd:milanpi:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1F64A4AA-A66B-4B2E-B8F1-F332E3945903"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:amd:genoapi_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F21375AC-B510-4A7C-8382-D98710569550",
"versionEndExcluding": "1.0.0.3"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:amd:genoapi:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "0EC5CF20-1E17-4F25-A186-5AFD1D0AC641"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "psirt@amd.com"
}