CVE-2023-20522 is a denial-of-service vulnerability affecting AMD MilanPI and RomePI firmware due to insufficient input validation in the ASP. This high-severity flaw (CVSS 7.5) can be triggered remotely with low attack complexity, allowing an attacker with a malicious BIOS to disrupt system availability. There is currently no public exploit code, active exploitation, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0.5CPE matchmatch criteria | cpe:2.3:o:amd:milanpi_firmware:*:*:*:*:*:*:*:* | ||
< 100dCPE matchmatch criteria | cpe:2.3:o:amd:romepi_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.