CVE-2023-20584 describes a medium-severity vulnerability affecting AMD processors, where the IOMMU improperly handles specific address ranges with invalid device table entries. This flaw allows a highly-privileged attacker within a compromised hypervisor to bypass SEV-SNP RMP checks, potentially compromising guest integrity. The attack requires local access and high privileges, but has a high impact on integrity. Currently, there is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< genoapi_1.0.0.bCPE matchmatch criteria | cpe:2.3:o:amd:epyc_8024pn_firmware:*:*:*:*:*:*:*:* | ||
< genoapi_1.0.0.bCPE matchmatch criteria | cpe:2.3:o:amd:epyc_8024p_firmware:*:*:*:*:*:*:*:* | ||
< genoapi_1.0.0.bCPE matchmatch criteria | cpe:2.3:o:amd:epyc_8124pn_firmware:*:*:*:*:*:*:*:* | ||
< genoapi_1.0.0.bCPE matchmatch criteria | cpe:2.3:o:amd:epyc_8124p_firmware:*:*:*:*:*:*:*:* | ||
< genoapi_1.0.0.bCPE matchmatch criteria | cpe:2.3:o:amd:epyc_8224pn_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.