CVE-2023-20576
Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS probability
- 0.13%
- CWE
- CWE-345
- Published
- 2026-09-02
- Last modified
- 2026-09-04
Affected products
- AMD AMD Ryzen™ 3000 Series Desktop Processors
- AMD AMD Ryzen™ 5000 Series Desktop Processors
- AMD AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 7000 Series Processors
- AMD AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics
- AMD AMD Ryzen™ Threadripper™ PRO 5000WX Processors
- AMD AMD Ryzen™ 7020 Series Processors with Radeon™ Graphics
- AMD AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics
Weakness type
Related vulnerabilities
- CVE-2026-80172 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-73316 — XenForo < 2.3.13 Payment Replay via PayPal REST Payment Provider
- CVE-2026-85008 — undici vulnerable to caching and replay of unsafe HTTP method responses
- CVE-2026-85621 — LobeChat 2.2.1 Webhook Signature Verification Bypass QQ Feishu
- CVE-2026-85435 — MOOS-IvP through 24.8.1 uFldNodeBroker Unauthenticated Shore Route Enrollment
- CVE-2026-85434 — MOOS-IvP through 24.8.1 uFldShoreBroker Bridge Route Injection via Unverified Node Ping
- CVE-2026-85431 — MOOS essential-moos through 10.0.1 pMOOSBridge Unauthenticated UDP Packet Injection
- CVE-2026-85430 — MOOS essential-moos through 10.0.1 pShare Unauthenticated UDP Datagram Republishing