CVE-2023-20540: AMD Ryzen 3000 Series Desktop Processors

Low severity, CVSS 1.8. EPSS: 0.2% chance of exploitation in the next 30 days.

An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary message input, potentially leading to a loss of data integrity.

Affected products

  • AMD AMD Ryzen 3000 Series Desktop Processors
  • AMD AMD Ryzen 5000 Series Desktop Processors
  • AMD AMD Ryzen Threadripper 3000 Series Processors
  • AMD AMD Ryzen Threadripper Pro 3000wx Series Processors
  • AMD AMD Ryzen Threadripper Pro 5000 Wx-Series Processors

Published 2026-06-26. Last modified 2026-06-26.