CVE-2022-23820
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
Failure to validate the AMD SMM communication buffer
may allow an attacker to corrupt the SMRAM potentially leading to arbitrary
code execution.
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Affected products
AMD · 3rd Gen AMD EPYC™ ProcessorsAMD · AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics “Picasso” AM4AMD · AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Pollock”AMD · AMD EPYC™ Embedded 7003AMD · AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ Graphics “Picasso” FP5AMD · AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics “Renoir” FP6AMD · AMD Ryzen™ 5000 Series Desktop Processors “Vermeer”AMD · AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics “Cezanne”AMD · AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics “Cezanne”AMD · AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics “Lucienne”AMD · AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics “Barcelo”AMD · AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics "Rembrandt"AMD · AMD Ryzen™ 7030 Series Mobile Processors with Radeon™ Graphics “Barcelo-R”AMD · AMD Ryzen™ 7035 Series Processors with Radeon™ Graphics “Rembrandt-R”AMD · AMD Ryzen™ Threadripper™ 2000 Series Processors “Colfax”AMD · AMD Ryzen™ Threadripper™ 3000 Series Processors “Castle Peak” HEDTAMD · AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors “Chagall” WSAMD · AMD Ryzen™ Threadripper™ PRO Processors “Castle Peak” WS SP3AMD · Ryzen™ 3000 series Desktop Processors “Matisse"