CVE-2023-20592: Medium severity amd epyc server firmware vulnerability

Published Oct 17, 2023
·
Updated

AMD Processors could provide weaker than expected security, caused by improper or unexpected behavior of the INVD instruction. A remote authenticated attacker could exploit this vulnerability to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

Other sources

Improper or unexpected behavior of the INVD in some of AMD CPU's may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU, potentially leading to a loss of guest virtual machine (VM) memory integrity.

Reference: https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3005.html

Red Hat

Improper or unexpected behavior of the INVD instruction in some AMD CPUs may allow an attacker with a malicious hypervisor to affect cache line write-back behavior of the CPU leading to a potential loss of guest virtual machine (VM) memory integrity.

MITRE

Affected Software

140 affected components
All of the following
AMD Epyc 7001 Firmware
AMD Epyc 7001
All of the following
AMD Epyc 7251 Firmware
AMD Epyc 7251
All of the following
AMD Epyc 7261 Firmware
AMD Epyc 7261
All of the following
AMD Epyc 7281 Firmware
AMD Epyc 7281
All of the following
AMD Epyc 7301 Firmware
AMD Epyc 7301
All of the following
AMD Epyc 7351 Firmware
AMD Epyc 7351
All of the following
AMD Epyc 7351p Firmware
AMD Epyc 7351p
All of the following
AMD Epyc 7371 Firmware
AMD Epyc 7371
All of the following
AMD Epyc 7401 Firmware
AMD Epyc 7401
All of the following
AMD Epyc 7401p Firmware
AMD Epyc 7401p
All of the following
AMD Epyc 7451 Firmware
AMD Epyc 7451
All of the following
AMD Epyc 7501 Firmware
AMD Epyc 7501
All of the following
AMD Epyc 7551 Firmware
AMD Epyc 7551
All of the following
AMD Epyc 7551p Firmware
AMD Epyc 7551p
All of the following
AMD Epyc 7601 Firmware
AMD Epyc 7601
All of the following
AMD Epyc 7232p Firmware
AMD Epyc 7232p
All of the following
AMD Epyc 7252 Firmware
AMD Epyc 7252
All of the following
AMD Epyc 7262 Firmware
AMD Epyc 7262
All of the following
AMD Epyc 7272 Firmware
AMD Epyc 7272
All of the following
AMD Epyc 7282 Firmware
AMD Epyc 7282
All of the following
AMD Epyc 7302 Firmware
AMD Epyc 7302
All of the following
AMD Epyc 7302p Firmware
AMD Epyc 7302p
All of the following
AMD Epyc 7352 Firmware
AMD Epyc 7352
All of the following
AMD Epyc 7402 Firmware
AMD Epyc 7402
All of the following
AMD Epyc 7402p Firmware
AMD Epyc 7402p
All of the following
AMD Epyc 7452 Firmware
AMD Epyc 7452
All of the following
AMD Epyc 7502 Firmware
AMD Epyc 7502
All of the following
AMD Epyc 7502p Firmware
AMD Epyc 7502p
All of the following
AMD Epyc 7532 Firmware
AMD Epyc 7532
All of the following
AMD Epyc 7542 Firmware
AMD Epyc 7542
All of the following
AMD Epyc 7552 Firmware
AMD Epyc 7552
All of the following
AMD Epyc 7642 Firmware
AMD Epyc 7642
All of the following
AMD Epyc 7662 Firmware
AMD Epyc 7662
All of the following
AMD Epyc 7702 Firmware
AMD Epyc 7702
All of the following
AMD Epyc 7702p Firmware
AMD Epyc 7702p
All of the following
AMD Epyc 7742 Firmware
AMD Epyc 7742
All of the following
AMD Epyc 7f32 Firmware
AMD Epyc 7f32
All of the following
AMD Epyc 7f52 Firmware
AMD Epyc 7f52
All of the following
AMD Epyc 7f72 Firmware
AMD Epyc 7f72
All of the following
AMD Epyc 7h12 Firmware
AMD Epyc 7h12
All of the following
AMD Epyc 7763 Firmware<milanpi_1.0.0.c
AMD Epyc 7763
All of the following
AMD Epyc 7713p Firmware<milanpi_1.0.0.c
AMD Epyc 7713p
All of the following
AMD Epyc 7713 Firmware<milanpi_1.0.0.c
AMD Epyc 7713
All of the following
AMD Epyc 7663p Firmware<milanpi_1.0.0.c
AMD Epyc 7663p
All of the following
AMD Epyc 7663 Firmware<milanpi_1.0.0.c
AMD Epyc 7663
All of the following
AMD Epyc 7643p Firmware<milanpi_1.0.0.c
AMD Epyc 7643p
All of the following
AMD Epyc 7773x Firmware<milanpi_1.0.0.c
AMD Epyc 7773x
All of the following
AMD Epyc 7643 Firmware<milanpi_1.0.0.c
AMD Epyc 7643
All of the following
AMD Epyc 7573x Firmware<milanpi_1.0.0.c
AMD Epyc 7573x
All of the following
AMD Epyc 75f3 Firmware<milanpi_1.0.0.c
AMD Epyc 75f3
All of the following
AMD Epyc 7543p Firmware<milanpi_1.0.0.c
AMD Epyc 7543p
All of the following
AMD Epyc 7543 Firmware<milanpi_1.0.0.c
AMD Epyc 7543
All of the following
AMD Epyc 7513 Firmware<milanpi_1.0.0.c
AMD Epyc 7513
All of the following
AMD Epyc 7473x Firmware<milanpi_1.0.0.c
AMD Epyc 7473x
All of the following
AMD Epyc 7453 Firmware<milanpi_1.0.0.c
AMD Epyc 7453
All of the following
AMD Epyc 74f3 Firmware<milanpi_1.0.0.c
AMD Epyc 74f3
All of the following
AMD Epyc 7443p Firmware<milanpi_1.0.0.c
AMD Epyc 7443p
All of the following
AMD Epyc 7443 Firmware<milanpi_1.0.0.c
AMD Epyc 7443
All of the following
AMD Epyc 7413 Firmware<milanpi_1.0.0.c
AMD Epyc 7413
All of the following
AMD Epyc 7373x Firmware<milanpi_1.0.0.c
AMD Epyc 7373x
All of the following
AMD Epyc 73f3 Firmware<milanpi_1.0.0.c
AMD Epyc 73f3
All of the following
AMD Epyc 7343 Firmware<milanpi_1.0.0.c
AMD Epyc 7343
All of the following
AMD Epyc 7313p Firmware<milanpi_1.0.0.c
AMD Epyc 7313p
All of the following
AMD Epyc 7313 Firmware<milanpi_1.0.0.c
AMD Epyc 7313
All of the following
AMD Epyc 7303p Firmware<milanpi_1.0.0.c
AMD Epyc 7303p
All of the following
AMD Epyc 7303 Firmware<milanpi_1.0.0.c
AMD Epyc 7303
All of the following
AMD Epyc 72f3 Firmware<milanpi_1.0.0.c
AMD Epyc 72f3
All of the following
AMD Epyc 7203p Firmware<milanpi_1.0.0.c
AMD Epyc 7203p
All of the following
AMD Epyc 7203 Firmware<milanpi_1.0.0.c
AMD Epyc 7203
IBM QRadar SIEM<=7.5 - 7.5.0 UP9 IF03
IBM QRadar Incident Forensics<=7.5 - 7.5.0 UP9 IF03

Event History

Oct 17, 2023
Data Sourced
via Red Hat·07:23 AM
DescriptionSeverityAffected Software
Nov 14, 2023
CVE Published
via MITRE·06:54 PM
Data Sourced
via MITRE·06:54 PM
Description
Oct 17, 2024
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2023-20592?

CVE-2023-20592 is classified as a medium severity vulnerability affecting certain AMD processors.

2

How do I fix CVE-2023-20592?

To mitigate CVE-2023-20592, users should apply the firmware updates provided by AMD as detailed in the security bulletin.

3

What types of AMD processors are affected by CVE-2023-20592?

CVE-2023-20592 affects specific models in the AMD Epyc family of processors.

4

Can CVE-2023-20592 be exploited remotely?

Yes, CVE-2023-20592 can be exploited by a remote authenticated attacker under certain conditions.

5

What impact does CVE-2023-20592 have on virtual machines?

CVE-2023-20592 could potentially lead to a loss of data integrity in guest virtual machines by affecting cache line write-back behavior.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203