Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-20579

20
FAUCET Score

CVE-2023-20579 describes an Improper Access Control vulnerability within the AMD SPI protection feature, affecting AMD products. This flaw allows a highly privileged attacker (Ring0 access) to bypass security mechanisms. The vulnerability carries a CVSS score of 6.0 (Medium) and could lead to a loss of data integrity and system availability. Currently, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< comboam4v2pi_1.2.0.cCPE matchmatch criteria
cpe:2.3:o:amd:ryzen_7_5700g_firmware:*:*:*:*:*:*:*:*
< comboam4v2pi_1.2.0.cCPE matchmatch criteria
cpe:2.3:o:amd:ryzen_7_5700ge_firmware:*:*:*:*:*:*:*:*
< comboam4v2pi_1.2.0.cCPE matchmatch criteria
cpe:2.3:o:amd:ryzen_5_5600g_firmware:*:*:*:*:*:*:*:*
< comboam4v2pi_1.2.0.cCPE matchmatch criteria
cpe:2.3:o:amd:ryzen_5_5600gt_firmware:*:*:*:*:*:*:*:*
< comboam4v2pi_1.2.0.cCPE matchmatch criteria
cpe:2.3:o:amd:ryzen_5_5600ge_firmware:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.0MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
0.8
Impact Score
5.2
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.16%
Probability of exploitation in next 30 days
EPSS Percentile
6.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0016 is in the 40th percentile among its peer group of 3,720 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

chromepatch availablevia llm_extracted
View patch
falcopatch availablevia llm_extracted
View patch

Vendor Advisories (3)

chromellm-chrome-120421c7a7655e32HIGH

AMD Processors February 2024 Security Updates

Jun 26, 2024
falcollm-falco-b47d9c20c236b36bHIGH

AMD Processors February 2024 Security Updates

Jun 26, 2024
redhatCVE-2023-20579Important

hw: amd: SPI bypass

Feb 13, 2024

References

amd.com / en/corporate/product-security/bulletin/AMD-SB-7009
Vendor Advisory