CVE-2022-23817

EUVD-2022-28746
Insufficient checking of memory buffer in ASP Secure OS may allow an attacker with a malicious TA to read/write to the ASP Secure OS kernel virtual address space, potentially leading to privilege escalation.
Classic Buffer Overflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7 HIGH
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
amdryzen_3_3300x_firmware
𝑥
< comboam4v2_1.2.0.a
ADP
amdryzen_3_3300u_firmware
𝑥
< picassopi-fp5_1.0.0.e
ADP
amdryzen_3_pro_3200g_firmware
𝑥
< comboam4v2_pi_1.2.0.8
ADP
amdryzen_5_7500f_firmware
𝑥
< comboam5_1.0.8.0
ADP
amdryzen_threadripper_pro_3995wx_firmware
𝑥
< castlepeakpi-sp3r3_1.0.0.8
ADP
amdryzen_threadripper_pro_3995wx_firmware
𝑥
< castlepeakwspi-swrx8_1.0.0.a
ADP
amdryzen_threadripper_pro_5995wx_firmware
𝑥
< chagallwspi-swrx8_1.0.0.5
ADP
amdryzen_3_4300u_firmware
𝑥
< renoirpi-fp6_1.0.0.a
ADP
amdryzen_5_6600u_firmware
𝑥
< rembrandtpi-fp7_1.0.0.5
ADP
amdryzen_3_7335u_firmware
𝑥
< rembrandtpi-fp7_1.0.0.5
ADP
amdryzen_7_7745hx_firmware
𝑥
< dragonrangefl1pi_1.0.0.3b
ADP
amdryzen_5_5600x_firmware
𝑥
< comboam4v2_pi_1.2.0.8
ADP
amdryzen_3_5300g_firmware
𝑥
< cezannepi-fp6_1.0.0.c
ADP
amdryzen_3_5425c_firmware
𝑥
< cezannepi-fp6_1.0.0.c
ADP
amdathlon_pro_300ge_firmware
𝑥
< picassopi-fp5_1.0.0.e
ADP