
Cloud Vulnerability DB
A community-led vulnerabilities database
IOMMU improperly handles certain special address ranges with invalid device table entries (DTEs), which was identified as CVE-2023-20584. This vulnerability affects AMD EPYC processors and their platform components, particularly in the context of SEV-SNP (Secure Encrypted Virtualization - Secure Nested Paging) systems. The vulnerability was disclosed in August 2024 (AMD Bulletin, Red Hat Portal).
The vulnerability has been assigned a CVSS v3 base score of 5.3 (Medium) with the vector string CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N. The technical nature of the vulnerability involves improper handling of special address ranges with invalid device table entries in the IOMMU, which can lead to DTE faults that potentially bypass RMP (Resource Mapping Protection) checks in SEV-SNP environments (Red Hat Portal).
If successfully exploited, this vulnerability could lead to a loss of guest integrity in SEV-SNP environments. The impact is primarily focused on integrity with no direct effect on confidentiality or availability. The vulnerability requires an attacker to have privileges and a compromised Hypervisor to successfully exploit the weakness (AMD Bulletin).
The vulnerability requires local access (AV:L), high attack complexity (AC:H), and high privileges (PR:H) for exploitation. An attacker would need both privileges and a compromised Hypervisor to successfully exploit this vulnerability. No user interaction is required for the exploitation process (Red Hat Portal).
AMD has released firmware updates to address this vulnerability. For 3rd Gen AMD EPYC processors (Milan), the fix is available in MilanPI 1.0.0.C (2023-12-18) and SEV firmware version 1.55.9. For 4th Gen AMD EPYC processors (Genoa), the fix is included in GenoaPI 1.0.0.B (2023-12-15) and SEV firmware version 1.55.23. Users are recommended to update to these firmware versions to mitigate the vulnerability (AMD Bulletin).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."