Insufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escalation of privileges.
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 2300u firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 3300x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 4300g firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 3 4300ge firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 3 5125c firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 3 5300g firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 5300ge firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 3 5400u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 3 5425c firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 3 5425u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 2500u firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2600 firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2600h firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2600x firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2700 firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 2700x firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3500 firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3500x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3600 firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3600x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 3600xt firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 4600g firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 5 4600ge firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 5 5560u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5600g firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 5600ge firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 5 5600h firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5600hs firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5600u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5625c firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 5 5625u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 2700 firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 2700u firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 2700x firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 2800h firmwareNVD
Affected:< comboam4v2_pi_1.2.0.6cFixed in:comboam4v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 3700x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 3800x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 3800xt firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 4700g firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 7 4700ge firmwareNVD
Affected:< renoirpi-fp6_1.0.0.7Fixed in:renoirpi-fp6_1.0.0.7CVE-2023-20559derived from NVD
ryzen 7 5700g firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 5700ge firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 7 5800h firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 5800hs firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 5800u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 5825c firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 7 5825u firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 3900 firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 9 3900x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 9 3900xt firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 9 3950x firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen 9 5900hs firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 5900hx firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 5980hs firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 5980hx firmwareNVD
Affected:< cezannepi-fp6_1.0.0.9Fixed in:cezannepi-fp6_1.0.0.9CVE-2023-20559derived from NVD
ryzen 9 pro 3900 firmwareNVD
Affected:< comboam4_v2_pi_1.2.0.6cFixed in:comboam4_v2_pi_1.2.0.6cCVE-2023-20559derived from NVD
ryzen threadripper 2920x firmwareNVD
Affected:< summitpi-sp3r2_1.1.0.5Fixed in:summitpi-sp3r2_1.1.0.5CVE-2023-20559derived from NVD
ryzen threadripper 2950x firmwareNVD
Affected:< summitpi-sp3r2_1.1.0.5Fixed in:summitpi-sp3r2_1.1.0.5CVE-2023-20559derived from NVD
ryzen threadripper 2970wx firmwareNVD
Affected:< summitpi-sp3r2_1.1.0.5Fixed in:summitpi-sp3r2_1.1.0.5CVE-2023-20559derived from NVD
ryzen threadripper 2990wx firmwareNVD
Affected:< summitpi-sp3r2_1.1.0.5Fixed in:summitpi-sp3r2_1.1.0.5CVE-2023-20559derived from NVD
ryzen threadripper 3960x firmwareNVD
Affected:< castlepeakpi-sp3r3_1.0.0.6Fixed in:castlepeakpi-sp3r3_1.0.0.6CVE-2023-20559derived from NVD
ryzen threadripper 3970x firmwareNVD
Affected:< castlepeakpi-sp3r3_1.0.0.6Fixed in:castlepeakpi-sp3r3_1.0.0.6CVE-2023-20559derived from NVD
ryzen threadripper 3990x firmwareNVD
Affected:< castlepeakpi-sp3r3_1.0.0.6Fixed in:castlepeakpi-sp3r3_1.0.0.6CVE-2023-20559derived from NVD
ryzen threadripper pro 3795wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 3945wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 3955wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 3975wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 3995wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5945wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5955wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5965wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5975wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
ryzen threadripper pro 5995wx firmwareNVD
Affected:< castlepeakwspi-swrx8_1.0.0.9Fixed in:castlepeakwspi-swrx8_1.0.0.9CVE-2023-20559derived from NVD
TridentStack Control can deploy fixes like this automatically across your Windows, macOS, and Linux fleet. See how it works
Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.
CVSS v3 Vector
Exploitability
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionNone
ScopeUnchanged
Impact
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploit Intelligence
0.67%probability of exploitation in 30 days
48thpercentile
Moderate risk: more likely to be exploited than 48% of all known CVEs.
Published advisories record a fix for 74 affected products. The "How to fix" section on this page lists the fixed version and source advisory for each one, so apply the entry matching what you actually run.
Is CVE-2023-20559 being actively exploited?
Not that we know of. CVE-2023-20559 is not in the CISA Known Exploited Vulnerabilities catalog. Its EPSS score of 0.67% is the estimated probability that it will be exploited in the next 30 days. That is higher than 48% of all scored CVEs.
How severe is CVE-2023-20559?
CVE-2023-20559 has a CVSS v3 base score of 8.8, rated high. CVSS rates the technical impact if the vulnerability is exploited, not how likely that is, so weigh it alongside the exploit-prediction score when you decide what to patch first.
What does CVE-2023-20559 affect?
Published advisories record a fix for ryzen 3 2200u firmware (NVD), ryzen 3 2300u firmware (NVD), ryzen 3 3300x firmware (NVD), ryzen 3 4300g firmware (NVD), and 70 more. Only products with a sourced advisory are listed, so treat this as what we can cite rather than a complete inventory.
TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.
This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-02-25.