« Volver al listado

CVE-2023-31326

Estado: AplazadaBaja (2.8)—

Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution environment (TEE) driver, potentially leading to loss of confidentiality.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-31326",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-31326",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-09-08T20:04:35.581719Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "psirt@amd.com",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 2.8,
          "attackVector": "LOCAL",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.1
      }
    ]
  },
  "affected": [
    {
      "source": "psirt@amd.com",
      "affectedData": [
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics",
          "versions": [
            {
              "status": "unaffected",
              "version": "Cezanne-FP6_1.0.1.0"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 7030 Series Mobile processors with Radeon™ Graphics",
          "versions": [
            {
              "status": "unaffected",
              "version": "Cezanne-FP6_1.0.1.0"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 4000 Series Desktop Processors",
          "versions": [
            {
              "status": "unaffected",
              "version": "ComboAM4v2PI_1.2.0.CA"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 5000 Series Desktop Processors",
          "versions": [
            {
              "status": "unaffected",
              "version": "ComboAM4v2PI_1.2.0.CA"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 7040 Series Mobile Processors with Radeon™ Graphics",
          "versions": [
            {
              "status": "unaffected",
              "version": "PhoenixPI-FP8-FP7_1.1.0.2"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics",
          "versions": [
            {
              "status": "unaffected",
              "version": "Renoir-FP6_ 1.0.0.D"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics",
          "versions": [
            {
              "status": "unaffected",
              "version": "Rembrandt-FP7_1.0.0.A"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics",
          "versions": [
            {
              "status": "unaffected",
              "version": "Cezanne-FP6_1.0.1.0"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics",
          "versions": [
            {
              "status": "unaffected",
              "version": "MendocinoPI-FT6_1.0.0.6"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ Embedded V2000 Series Processors",
          "versions": [
            {
              "status": "unaffected",
              "version": "EmbeddedPI-FP6_1.0.0.A"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Ryzen™ Embedded V3000 Series Processors",
          "versions": [
            {
              "status": "unaffected",
              "version": "Embedded-PI_FP7r2 1009"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Radeon™ RX 7000 Series Graphics Products",
          "versions": [
            {
              "status": "unaffected",
              "version": "AMD Software: Adrenalin Edition 24.7.1 (24.10.29.01)"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Radeon™ PRO W7000 Series Graphics Products",
          "versions": [
            {
              "status": "unaffected",
              "version": "AMD Software: PRO Edition 24.Q2 (24.10.20)"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Instinct™ MI210",
          "versions": [
            {
              "status": "unaffected",
              "version": "ROCm 6.4"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Instinct™ MI250",
          "versions": [
            {
              "status": "unaffected",
              "version": "ROCm 6.4"
            }
          ],
          "defaultStatus": "affected"
        },
        {
          "vendor": "AMD",
          "product": "AMD Radeon™ PRO V710 Graphics Products",
          "versions": [
            {
              "status": "unaffected",
              "version": "Contact your AMD Customer Engineering representative"
            }
          ],
          "defaultStatus": "affected"
        }
      ]
    }
  ],
  "published": "2025-09-06T17:15:31.527",
  "references": [
    {
      "url": "https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-4012.html",
      "source": "psirt@amd.com"
    },
    {
      "url": "https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-5007.html",
      "source": "psirt@amd.com"
    },
    {
      "url": "https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6018.html",
      "source": "psirt@amd.com"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "psirt@amd.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-457"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Use of an uninitialized variable in the ASP could allow an attacker to access leftover data from a trusted execution environment (TEE) driver, potentially leading to loss of confidentiality."
    }
  ],
  "lastModified": "2026-06-17T05:56:48.253",
  "sourceIdentifier": "psirt@amd.com"
}