CVEFinder.io

CVE-2023-20548

âš ī¸ high
🔍 Scan for this CVE
Summary

A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to corrupt memory resulting in loss of integrity, confidentiality, or availability.

CVSS Score
7.8
High
EPSS Score
0.0
Exploit Probability
Published Date
2026-02-11
First Seen: 2026-02-12
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 69.6% of all 330,193 vulnerabilities in our database.

#100,417
Above average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Feb 11, 2026
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2026-03-05
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H
CVSS Vector 4.0 CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:H/VA:L/SC:L/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 2

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2024-36333 âš ī¸ high 7.8 0.0 A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potenti... 2026-05-15
CVE-2023-31324 âš ī¸ high 7.8 0.0 A Time-of-check time-of-use (TOCTOU) race condition in the AMD Secure Processor (ASP) could allow an attacker to modify ... 2026-02-11
CVE-2024-21937 âš ī¸ high 7.3 0.1 Incorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege esc... 2024-11-12
CVE-2021-26367 đŸ”ļ medium 5.7 0.0 A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an a... 2024-08-13
CVE-2023-20510 đŸ”ļ medium 4.7 0.0 An insufficient DRAM address validation in PMFW may allow a privileged attacker to read from an invalid DRAM address to ... 2024-08-13
CVE-2023-31307 â„šī¸ low 2.3 0.1 Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-o... 2024-08-13
These CVEs affect the same products