Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown

CVE-2023-20597

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Attacker Value
Unknown

CVE-2023-20594

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Attacker Value
Unknown

CVE-2023-20589

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
An attacker with specialized hardware and physical access to an impacted device may be able to perform a voltage fault injection attack resulting in compromise of the ASP secure boot potentially leading to arbitrary code execution. 
Attacker Value
Unknown

CVE-2023-20569

Disclosure Date: August 08, 2023 (last updated April 11, 2024)
A side channel vulnerability on some of the AMD CPUs may allow an attacker to influence the return address prediction. This may result in speculative execution at an attacker-controlled address, potentially leading to information disclosure.
Attacker Value
Unknown

CVE-2023-20555

Disclosure Date: August 08, 2023 (last updated October 08, 2023)
Insufficient input validation in CpmDisplayFeatureSmm may allow an attacker to corrupt SMM memory by overwriting an arbitrary bit in an attacker-controlled pointer potentially leading to arbitrary code execution in SMM.