Куда я попал?
SECURITM это SGRC система, ? автоматизирующая процессы в службах информационной безопасности. SECURITM помогает построить и управлять ИСПДн, КИИ, ГИС, СМИБ/СУИБ, банковскими системами защиты.
А еще SECURITM это место для обмена опытом и наработками для служб безопасности.

CVE-2023-20593

PUBLISHED 13.02.2025

CNA: AMD

Обновлено: 10.06.2024
An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

БДУ ФСТЭК

Идентификатор Описание
BDU:2023-03992 Уязвимость микропрограммного обеспечения процессоров AMD на базе микроархитектуры Zen2, позволяющая нарушителю отследить содержимого регистров во время выполнения других процессов на том же ядре CPU

Доп. Информация

Product Status

Ryzen™ 3000 Series Desktop Processors “Matisse” AM4
Product: Ryzen™ 3000 Series Desktop Processors “Matisse” AM4
Vendor: AMD
Default status: affected
Platforms:
  • x86
Версии:
Затронутые версии Статус
Наблюдалось в версии various affected
AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics “Renoir” AM4
Product: AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics “Renoir” AM4
Vendor: AMD
Default status: affected
Platforms:
  • x86
Версии:
Затронутые версии Статус
Наблюдалось в версии various affected
3rd Gen AMD Ryzen™ Threadripper™ Processors “Castle Peak” HEDT
Product: 3rd Gen AMD Ryzen™ Threadripper™ Processors “Castle Peak” HEDT
Vendor: AMD
Default status: affected
Platforms:
  • x86
Версии:
Затронутые версии Статус
Наблюдалось в версии various affected
Ryzen™ Threadripper™ PRO Processors “Castle Peak” WS SP3
Product: Ryzen™ Threadripper™ PRO Processors “Castle Peak” WS SP3
Vendor: AMD
Default status: affected
Platforms:
  • x86
Версии:
Затронутые версии Статус
Наблюдалось в версии various affected
Ryzen™ 5000 Series Mobile processors with Radeon™ Graphics “Lucienne”
Product: Ryzen™ 5000 Series Mobile processors with Radeon™ Graphics “Lucienne”
Vendor: AMD
Default status: affected
Platforms:
  • x86
Версии:
Затронутые версии Статус
Наблюдалось в версии various affected
Ryzen™ 4000 Series Mobile processors with Radeon™ Graphics “Renoir”
Product: Ryzen™ 4000 Series Mobile processors with Radeon™ Graphics “Renoir”
Vendor: AMD
Default status: affected
Platforms:
  • x86
Версии:
Затронутые версии Статус
Наблюдалось в версии various affected
Ryzen™ 7020 Series processors “Mendocino” FT6
Product: Ryzen™ 7020 Series processors “Mendocino” FT6
Vendor: AMD
Default status: affected
Platforms:
  • x86
Версии:
Затронутые версии Статус
Наблюдалось в версии various affected
2nd Gen AMD EPYC™ Processors
Product: 2nd Gen AMD EPYC™ Processors
Vendor: AMD
Default status: affected
Platforms:
  • x86
Версии:
Затронутые версии Статус
Наблюдалось в версии various affected
 

Ссылки

https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7008
http://xenbits.xen.org/xsa/advisory-433.html
http://www.openwall.com/lists/oss-security/2023/07/24/3
http://seclists.org/fulldisclosure/2023/Jul/43
http://www.openwall.com/lists/oss-security/2023/07/25/5
http://www.openwall.com/lists/oss-security/2023/07/25/6
http://www.openwall.com/lists/oss-security/2023/07/25/1
http://www.openwall.com/lists/oss-security/2023/07/25/13
http://www.openwall.com/lists/oss-security/2023/07/25/17
http://www.openwall.com/lists/oss-security/2023/07/25/12
http://www.openwall.com/lists/oss-security/2023/07/25/16
http://www.openwall.com/lists/oss-security/2023/07/25/14
http://www.openwall.com/lists/oss-security/2023/07/25/15
http://www.openwall.com/lists/oss-security/2023/07/26/1
https://cmpxchg8b.com/zenbleed.html
https://www.debian.org/security/2023/dsa-5459
https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html
https://www.debian.org/security/2023/dsa-5462
https://www.debian.org/security/2023/dsa-5461
https://lists.debian.org/debian-lts-announce/2023/07/msg00033.html
http://www.openwall.com/lists/oss-security/2023/07/31/2
https://lists.debian.org/debian-lts-announce/2023/08/msg00001.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SD2G74BXS2SWOE3FIQJ6X76S3...
http://www.openwall.com/lists/oss-security/2023/08/08/7
http://www.openwall.com/lists/oss-security/2023/08/08/8
http://www.openwall.com/lists/oss-security/2023/08/08/6
http://www.openwall.com/lists/oss-security/2023/08/16/4
http://www.openwall.com/lists/oss-security/2023/08/16/5
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CP6WQO3CDPLE5O635N7TAL5KC...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKKYIK2EASDNUV4I7EFJKNBVO...
http://www.openwall.com/lists/oss-security/2023/09/22/9
http://www.openwall.com/lists/oss-security/2023/09/22/11
http://www.openwall.com/lists/oss-security/2023/09/25/4
http://www.openwall.com/lists/oss-security/2023/09/25/7
https://security.netapp.com/advisory/ntap-20240531-0004/

CVE Program Container

Обновлено: 02.08.2024
SSVC and KEV, plus CVSS and CWE if not provided by the CNA.

Ссылки

https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7008
http://xenbits.xen.org/xsa/advisory-433.html
http://www.openwall.com/lists/oss-security/2023/07/24/3
http://seclists.org/fulldisclosure/2023/Jul/43
http://www.openwall.com/lists/oss-security/2023/07/25/5
http://www.openwall.com/lists/oss-security/2023/07/25/6
http://www.openwall.com/lists/oss-security/2023/07/25/1
http://www.openwall.com/lists/oss-security/2023/07/25/13
http://www.openwall.com/lists/oss-security/2023/07/25/17
http://www.openwall.com/lists/oss-security/2023/07/25/12
http://www.openwall.com/lists/oss-security/2023/07/25/16
http://www.openwall.com/lists/oss-security/2023/07/25/14
http://www.openwall.com/lists/oss-security/2023/07/25/15
http://www.openwall.com/lists/oss-security/2023/07/26/1
https://cmpxchg8b.com/zenbleed.html
https://www.debian.org/security/2023/dsa-5459
https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html
https://www.debian.org/security/2023/dsa-5462
https://www.debian.org/security/2023/dsa-5461
https://lists.debian.org/debian-lts-announce/2023/07/msg00033.html
http://www.openwall.com/lists/oss-security/2023/07/31/2
https://lists.debian.org/debian-lts-announce/2023/08/msg00001.html
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/SD2G74BXS2SWOE3FIQJ6X76S3...
http://www.openwall.com/lists/oss-security/2023/08/08/7
http://www.openwall.com/lists/oss-security/2023/08/08/8
http://www.openwall.com/lists/oss-security/2023/08/08/6
http://www.openwall.com/lists/oss-security/2023/08/16/4
http://www.openwall.com/lists/oss-security/2023/08/16/5
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/CP6WQO3CDPLE5O635N7TAL5KC...
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/HKKYIK2EASDNUV4I7EFJKNBVO...
http://www.openwall.com/lists/oss-security/2023/09/22/9
http://www.openwall.com/lists/oss-security/2023/09/22/11
http://www.openwall.com/lists/oss-security/2023/09/25/4
http://www.openwall.com/lists/oss-security/2023/09/25/7
https://security.netapp.com/advisory/ntap-20240531-0004/

CISA ADP Vulnrichment

Обновлено: 19.11.2024
Этот блок содержит дополнительную информацию, предоставленную программой CVE для этой уязвимости.

SSVC

Exploitation Automatable Technical Impact Версия Дата доступа
poc no partial 2.0.3 19.11.2024

Мы используем cookie-файлы, чтобы получить статистику, которая помогает нам улучшить сервис для вас с целью персонализации сервисов и предложений. Вы может прочитать подробнее о cookie-файлах или изменить настройки браузера. Продолжая пользоваться сайтом, вы даёте согласие на использование ваших cookie-файлов и соглашаетесь с Политикой обработки персональных данных.