CVE-2023-31315 describes an improper validation vulnerability in an AMD model specific register, potentially allowing a malicious program with ring0 access to modify SMM configuration and achieve arbitrary code execution. While the CVSS score is 7.5 HIGH, indicating significant impact, AMD states it primarily affects "seriously breached systems." There is no evidence of active exploitation, nor are public exploit tools available, though it has garnered notable community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | 1st Gen AMD EPYC™ Processors | >= various, < Naples PI 1.0.0.MCNA affecteddefault affected | |
| AMD | 2nd Gen AMD EPYC™ Processors | >= various, < Rome PI 1.0.0.JCNA affecteddefault affected | |
| AMD | 4th Gen AMD EPYC™ Processors | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD Athlon™ 3000 Series Mobile Processors With Radeon™ Graphics | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD EPYC™ Embedded 3000 | variousCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025HP ThinPro 8.1 SP6 Security Updates
Mar 3, 2025hw: amd: SMM Lock Bypass
Aug 9, 2024