CVE-2023-31339 MEDIUM

CVE-2023-31339

Vendor Amd
Product Zynq™ UltraScale+™ MPSoC/RFSoC
Weakness CWE-20 · Input validation
Published August 13, 2024
Last update August 15, 2024

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required High
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:H

What the vulnerability does

01Description

Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.

Key dates

02Disclosure timeline

August 13, 2024 CVE published
August 15, 2024 Record updated