CVE & CISA-KEV Catalog

CVE-2023-20559

HIGH
8.8
CVSS v3
NVD

Description

Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.

How to fix

Remediation Available
ryzen 3 2200u firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 2300u firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 3300x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 4300g firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 3 4300ge firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 3 5125c firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 3 5300g firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 5300ge firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 5400u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 3 5425c firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 3 5425u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 2500u firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2600 firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2600h firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2600x firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2700 firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2700x firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3500 firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3500x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3600 firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3600x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3600xt firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 4600g firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 5 4600ge firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 5 5560u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5600g firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 5600ge firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 5600h firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5600hs firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5600u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5625c firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5625u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 2700 firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 2700u firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 2700x firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 2800h firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 3700x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 3800x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 3800xt firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 4700g firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 7 4700ge firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 7 5700g firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 5700ge firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 5800h firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 5800hs firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 5800u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 5825c firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 5825u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 3900 firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 9 3900x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 9 3900xt firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 9 3950x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 9 5900hs firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 5900hx firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 5980hs firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 5980hx firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 pro 3900 firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen threadripper 2920x firmwareNVD
Affected:< summitpi-sp3r2_1.1.0.5Fixed in:summitpi-sp3r2_1.1.0.5CVE-2023-20559derived from NVD
ryzen threadripper 2950x firmwareNVD
Affected:< summitpi-sp3r2_1.1.0.5Fixed in:summitpi-sp3r2_1.1.0.5CVE-2023-20559derived from NVD
ryzen threadripper 2970wx firmwareNVD
Affected:< summitpi-sp3r2_1.1.0.5Fixed in:summitpi-sp3r2_1.1.0.5CVE-2023-20559derived from NVD
ryzen threadripper 2990wx firmwareNVD
Affected:< summitpi-sp3r2_1.1.0.5Fixed in:summitpi-sp3r2_1.1.0.5CVE-2023-20559derived from NVD
ryzen threadripper 3960x firmwareNVD
Affected:< castlepeakpi-sp3r3_1.0.0.6Fixed in:castlepeakpi-sp3r3_1.0.0.6CVE-2023-20559derived from NVD
ryzen threadripper 3970x firmwareNVD
Affected:< castlepeakpi-sp3r3_1.0.0.6Fixed in:castlepeakpi-sp3r3_1.0.0.6CVE-2023-20559derived from NVD
ryzen threadripper 3990x firmwareNVD
Affected:< castlepeakpi-sp3r3_1.0.0.6Fixed in:castlepeakpi-sp3r3_1.0.0.6CVE-2023-20559derived from NVD
ryzen threadripper pro 3795wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 3945wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 3955wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 3975wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 3995wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5945wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5955wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5965wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5975wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5995wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityHigh
AvailabilityHigh

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Exploit Intelligence

0.67%probability of exploitation in 30 days
47thpercentile

Moderate risk: more likely to be exploited than 47% of all known CVEs.

References

Vendor Advisory1
Embed a live status badge for CVE-2023-20559
CVE-2023-20559 severity badge

Markdown

[![CVE-2023-20559](https://tridentstack.com/cve/badge/CVE-2023-20559.svg)](https://tridentstack.com/cve/CVE-2023-20559)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-20559"><img src="https://tridentstack.com/cve/badge/CVE-2023-20559.svg" alt="CVE-2023-20559"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-02-25.