
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2023-20566 is a security vulnerability related to improper address validation in ASP (AMD Secure Processor) when SNP (Secure Nested Paging) is enabled. The vulnerability was disclosed on November 14, 2023, affecting various AMD EPYC processors and their firmware versions (AMD Advisory).
The vulnerability has received varying severity ratings, with NIST assigning a CVSS v3.1 Base Score of 7.5 (HIGH) with vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N, while AMD assigned a CVSS score of 5.3 (MEDIUM) with vector string CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N (NVD).
The vulnerability could potentially allow an attacker to compromise guest memory integrity in systems where SNP is enabled (AMD Advisory).
AMD has released firmware updates to address this vulnerability. The fixes are included in firmware versions milanpi1.0.0.b for Milan processors and genoapi1.0.0.7 for Genoa processors (AMD Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."