CVE & CISA-KEV Catalog

CVE-2023-20591

MEDIUM
6.5
CVSS v3
NVD

Description

Improper re-initialization of IOMMU during the DRTM event may permit an untrusted platform configuration to persist, allowing an attacker to read or modify hypervisor memory, potentially resulting in loss of confidentiality, integrity, and availability.

How to fix

Remediation Available
epyc 7203 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7203p firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 72f3 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7303 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7303p firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7313 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7313p firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7343 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7373x firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 73f3 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7413 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7443 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7443p firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7453 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7473x firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 74f3 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7513 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7543 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7543p firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7573x firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 75f3 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7643 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7643p firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7663 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7663p firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7713 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7713p firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7763 firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 7773x firmwareNVD
Affected:< milanpi_1.0.0.bFixed in:milanpi_1.0.0.bCVE-2023-20591derived from NVD
epyc 8024p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8024pn firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8124p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8124pn firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8224p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8224pn firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8324p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8324pn firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8434p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8434pn firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8534p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 8534pn firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9124 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9174f firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9184x firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9224 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9254 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9274f firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9334 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9354 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9354p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9374f firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9384x firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9454 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9454p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9474f firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9534 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9554 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9554p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9634 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9654 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9654p firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9684x firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9734 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9754 firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD
epyc 9754s firmwareNVD
Affected:< genoapi_1.0.0.8Fixed in:genoapi_1.0.0.8CVE-2023-20591derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityHigh
Privileges RequiredNone
User InteractionNone
ScopeChanged

Impact

ConfidentialityLow
IntegrityLow
AvailabilityLow

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L

Exploit Intelligence

0.30%probability of exploitation in 30 days
22ndpercentile

Low risk: more likely to be exploited than 22% of all known CVEs.

References

Vendor Advisory1
Embed a live status badge for CVE-2023-20591
CVE-2023-20591 severity badge

Markdown

[![CVE-2023-20591](https://tridentstack.com/cve/badge/CVE-2023-20591.svg)](https://tridentstack.com/cve/CVE-2023-20591)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-20591"><img src="https://tridentstack.com/cve/badge/CVE-2023-20591.svg" alt="CVE-2023-20591"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2025-03-13.