« Back to list

CVE-2023-20587

Status: DeferredHigh (7.1)—

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

⚠ AI-inferred from the description — NVD hasn't analyzed this CVE yet, these aren't verified CPEs.

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2023-20587",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-20587",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-02-14T19:17:11.969537Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.1,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.2,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@amd.com",
      "affectedData": [
        {
          "vendor": "AMD",
          "product": "3rd Gen AMD EPYC™ Processors",
          "versions": [
            {
              "status": "affected",
              "version": "various "
            }
          ],
          "platforms": [
            "x86"
          ],
          "packageName": "PI",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "AMD",
          "product": "4th Gen AMD EPYC™ Processors",
          "versions": [
            {
              "status": "affected",
              "version": "various"
            }
          ],
          "platforms": [
            "x86"
          ],
          "packageName": "PI",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "AMD",
          "product": "1st Gen AMD EPYC™ Processors",
          "versions": [
            {
              "status": "affected",
              "version": "various"
            }
          ],
          "packageName": "PI",
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "2nd Gen AMD EPYC™ Processors",
          "versions": [
            {
              "status": "affected",
              "version": "various"
            }
          ],
          "platforms": [
            "x86"
          ],
          "packageName": "PI",
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "AMD",
          "product": "AMD EPYC(TM) Embedded 3000 ",
          "versions": [
            {
              "status": "affected",
              "version": "various"
            }
          ],
          "platforms": [
            "x86"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "AMD",
          "product": "AMD EPYC(TM) Embedded 7002 ",
          "versions": [
            {
              "status": "affected",
              "version": "various"
            }
          ],
          "platforms": [
            "x86"
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "AMD",
          "product": "AMD EPYC(TM) Embedded 7003",
          "versions": [
            {
              "status": "affected",
              "version": "various"
            }
          ],
          "defaultStatus": "unaffected"
        },
        {
          "vendor": "AMD",
          "product": "AMD EPYC(TM) Embedded 9003",
          "versions": [
            {
              "status": "affected",
              "version": "various"
            }
          ],
          "platforms": [
            "x86"
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2024-02-13T20:15:52.677",
  "references": [
    {
      "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7009",
      "source": "psirt@amd.com"
    },
    {
      "url": "https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7009",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-284"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper\nAccess Control in System Management Mode (SMM) may allow an attacker access to\nthe SPI flash potentially leading to arbitrary code execution.\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n\n"
    },
    {
      "lang": "es",
      "value": "Un control de acceso inadecuado en el modo de administración del sistema (SMM) puede permitir que un atacante acceda a la memoria flash SPI, lo que podría provocar la ejecución de código arbitrario."
    }
  ],
  "lastModified": "2026-06-17T05:30:22.307",
  "sourceIdentifier": "psirt@amd.com"
}