Improper input validation in ARM® Trusted Firmware used in AMD’s Zynq™ UltraScale+™) MPSoC/RFSoC may allow a privileged attacker to perform out of bound reads, potentially resulting in data leakage and denial of service.
References
Link | Resource |
---|---|
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8002 | Broken Link |
Configurations
Configuration 1 (hide)
AND |
|
History
27 Nov 2024, 15:55
Type | Values Removed | Values Added |
---|---|---|
First Time |
Amd zu49dr
Amd zu29dr Amd zu3cg Amd zu5ev Amd zu21dr Arm trusted Firmware-a Amd zu27dr Amd zu9eg Amd zu15eg Amd zu25dr Amd zu1eg Amd zu4eg Amd zu46dr Amd zu6eg Amd zu42dr Amd zu3tcg Amd zu28dr Amd zu47dr Amd zu7eg Amd zu4ev Amd zu3eg Amd zu48dr Amd zu17eg Amd Amd zu64dr Amd zu43dr Amd zu65dr Amd zu63dr Amd zu4cg Amd zu5eg Amd zu9cg Amd zu7ev Amd zu6cg Amd zu67dr Amd zu2eg Amd zu11eg Amd zu7cg Amd zu19eg Amd zu2cg Arm Amd trusted Firmware-a Amd zu1cg Amd zu5cg Amd zu39dr Amd zu3teg |
|
CPE | cpe:2.3:h:amd:zu39dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu27dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu3tcg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu43dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu19eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu63dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu9eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu3eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu65dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu5cg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu5ev:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu11eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu15eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu67dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu4ev:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu1eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu3cg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu7eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu64dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu17eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu4cg:-:*:*:*:*:*:*:* cpe:2.3:o:arm:trusted_firmware-a:*:*:*:*:*:*:*:* cpe:2.3:h:amd:zu42dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu6eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu21dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu4eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu1cg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu47dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu7ev:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu25dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu2cg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu2eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu49dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu9cg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu5eg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu28dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu46dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu48dr:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu3teg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu7cg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu6cg:-:*:*:*:*:*:*:* cpe:2.3:h:amd:zu29dr:-:*:*:*:*:*:*:* cpe:2.3:o:amd:trusted_firmware-a:*:*:*:*:*:*:*:* |
|
CWE | CWE-125 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.8 |
References | () https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8002 - Broken Link |
13 Aug 2024, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-13 17:15
Updated : 2024-11-27 15:55
NVD link : CVE-2023-31339
Mitre link : CVE-2023-31339
JSON object : View
Products Affected
amd
- zu2cg
- zu64dr
- trusted_firmware-a
- zu1eg
- zu4eg
- zu5cg
- zu7ev
- zu15eg
- zu49dr
- zu6cg
- zu27dr
- zu9eg
- zu25dr
- zu4cg
- zu3tcg
- zu42dr
- zu17eg
- zu4ev
- zu65dr
- zu3teg
- zu39dr
- zu6eg
- zu63dr
- zu3eg
- zu19eg
- zu5ev
- zu21dr
- zu1cg
- zu5eg
- zu67dr
- zu28dr
- zu7eg
- zu2eg
- zu3cg
- zu29dr
- zu47dr
- zu48dr
- zu43dr
- zu9cg
- zu46dr
- zu7cg
- zu11eg
arm
- trusted_firmware-a
CWE
CWE-125
Out-of-bounds Read