Skip to main content

Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation

CVE-2023-31316

Severity High
Score 7.1/10

Summary

Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability to write outside the trusted memory range (TMR) to change the execution flow of the Video Core Next (VCN) firmware potentially impacting confidentiality, integrity, or availability.

  • HIGH
  • LOCAL
  • NONE
  • LOW

CWE-1304 - Improperly Preserved Integrity of Hardware Configuration State During a Power Save/Restore Operation

The product performs a power save/restore operation, but it does not ensure that the integrity of the configuration state is maintained and/or verified between the beginning and ending of the operation.

References

Advisory Timeline

  • Published