CVE-2023-20566: Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.

5.3 CVSS

Description

Improper address validation in ASP with SNP enabled may potentially allow an attacker to compromise guest memory integrity.

Classification

CVE ID: CVE-2023-20566

CVSS Base Severity: MEDIUM

CVSS Base Score: 5.3

Affected Products

Vendor: AMD

Product: 3rd Gen AMD EPYC™ Processors

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.06% (probability of being exploited)

EPSS Percentile: 30.55% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-3002

Timeline