CVE-2023-31307: Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within...

2.3 CVSS

Description

Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.

Classification

CVE ID: CVE-2023-31307

CVSS Base Severity: LOW

CVSS Base Score: 2.3

Affected Products

Vendor: AMD

Product: AMD Radeon™ RX 6000 Series Graphics Cards

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.amd.com/en/resources/product-security/bulletin/amd-sb-6005.html

Timeline