
Cloud Vulnerability DB
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
CVE-2022-23830 is a security vulnerability affecting AMD EPYC processors where the System Management Mode (SMM) configuration may not be immutable when Secure Nested Paging (SNP) is enabled. This vulnerability was disclosed in November 2023 and affects multiple AMD EPYC processor families including 7003 series (Milan) and 9004 series (Genoa) processors (AMD Advisory).
The vulnerability stems from an issue where the SMM configuration lacks proper immutability when SNP is enabled. The severity of this vulnerability has been assessed with different CVSS v3.1 scores: NIST rates it as MEDIUM with a base score of 5.3 (Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N), while AMD rates it as LOW with a base score of 1.9 (Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:N) (NVD).
The vulnerability can potentially result in a limited loss of guest memory integrity when exploited. This affects systems where SNP (Secure Nested Paging) is enabled, potentially compromising the security guarantees provided by the virtualization environment (AMD Advisory).
AMD has released firmware updates to address this vulnerability. For Milan processors, the fix is available in version milanpi1.0.0.a and later, while for Genoa processors, the fix is included in version genoapi1.0.0.1 and later (AMD Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
An open project to list all known cloud vulnerabilities and Cloud Service Provider security issues
A comprehensive threat intelligence database of cloud security incidents, actors, tools and techniques
A step-by-step framework for modeling and improving SaaS and PaaS tenant isolation
Get a personalized demo
“Best User Experience I have ever seen, provides full visibility to cloud workloads.”
“Wiz provides a single pane of glass to see what is going on in our cloud environments.”
“We know that if Wiz identifies something as critical, it actually is.”