CVE-2023-20518: AMD Athlon 3000 Series Desktop Processors With Radeon Graphics
Low severity, CVSS 1.9. EPSS: 0.1% chance of exploitation in the next 30 days.
Incomplete cleanup in the ASP may expose the Master Encryption Key (MEK) to a privileged attacker with access to the BIOS menu or UEFI shell and a memory exfiltration vulnerability, potentially resulting in loss of confidentiality.
Affected products
- AMD AMD Athlon 3000 Series Desktop Processors With Radeon Graphics
- AMD AMD Athlon 3000 Series Mobile Processors With Radeon Graphics
- AMD AMD Epyc 9004 Series Processors
- AMD AMD Ryzen 3000 Series Desktop Processors
- AMD AMD Ryzen 3000 Series Mobile Processor With Radeon Graphics
- AMD AMD Ryzen 3000 Series Processors With Radeon Graphics
- AMD AMD Ryzen 4000 Series Desktop Processors With Radeon Graphics
- AMD AMD Ryzen 4000 Series Mobile Processors With Radeon Graphics
- AMD AMD Ryzen 5000 Series Desktop Processor With Radeon Graphics
- AMD AMD Ryzen 5000 Series Desktop Processors
- AMD AMD Ryzen 5000 Series Mobile Processors With Radeon Graphics
- AMD AMD Ryzen 5000 Series Processors With Radeon Graphics
- AMD AMD Ryzen 6000 Series Processors With Radeon Graphics
- AMD AMD Ryzen 7000 Series Desktop Processors
- AMD AMD Ryzen 7020 Series Processors With Radeon Graphics
- AMD AMD Ryzen 7035 Series Processors With Radeon Graphics
- AMD AMD Ryzen Embedded 5000 Series Processors
- AMD AMD Ryzen Embedded 7000 Series Processors
- AMD AMD Ryzen Embedded r1000 Series Processors
- AMD AMD Ryzen Embedded r2000 Series Processors
- AMD AMD Ryzen Embedded v1000 Series Processors
- AMD AMD Ryzen Embedded v2000 Series Processors
- AMD AMD Ryzen Embedded v3000 Series Processors
- AMD AMD Ryzen Threadripper 3000 Series Processors
- AMD AMD Ryzen Threadripper Pro 3000wx Series Processors
- and 1 more
Published 2024-08-13. Last modified 2026-06-17.