CVE-2023-31317
Last modified
CVE-2023-31317 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Improper restriction of operations within the bounds of a memory buffer in the AMD secure processer (ASP) could allow an attacker to read or write to protected memory potentially resulting in arbitrary code execution.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AMD | AMD Radeon™ RX 6000 Series Graphics Products | All versions |
| AMD | AMD Radeon™ RX 7000 Series Graphics Products | All versions |
| AMD | AMD Radeon™ PRO W7000 Series Graphics Products | All versions |
| AMD | AMD Radeon™ PRO W6000 Series Graphics Products | All versions |
| AMD | AMD Instinct™ MI250 | All versions |
| AMD | AMD Instinct™ MI210 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2023-31317?
How severe is CVE-2023-31317?
How do I fix CVE-2023-31317?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-31309Improper validation in Power Management Firmware (PMFW) may …6.8
- CVE-2023-3131The MStore API WordPress plugin before 3.9.7 does not secure…4.3
- CVE-2023-31310Improper input validation in Power Management Firmware (PMFW…5
- CVE-2023-31313An unintended proxy or intermediary in the AMD power managem…7.2
- CVE-2023-31315Improper validation in a model specific register (MSR) could…7.5
- CVE-2023-31316Improperly preserved integrity of hardware configuration sta…7.1
- CVE-2023-3132The MainWP Child plugin for WordPress is vulnerable to Sensi…7.5
- CVE-2023-31320Improper input validation in the AMD RadeonTM Graphics displ…7.5
- CVE-2023-31322Type confusion in the ASP could allow an attacker to pass a …8.7
- CVE-2023-31323Type confusion in the AMD Secure Processor (ASP) could allow…8.4
- CVE-2023-31324A Time-of-check time-of-use (TOCTOU) race condition in the A…7.8
- CVE-2023-31325Improper isolation of shared resources on System-on-a-chip (…7.2
Are you affected by CVE-2023-31317?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
