CVE-2023-20540: AMD Ryzen 3000 Series Desktop Processors
Low severity, CVSS 1.8. EPSS: 0.2% chance of exploitation in the next 30 days.
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary message input, potentially leading to a loss of data integrity.
Affected products
- AMD AMD Ryzen 3000 Series Desktop Processors
- AMD AMD Ryzen 5000 Series Desktop Processors
- AMD AMD Ryzen Threadripper 3000 Series Processors
- AMD AMD Ryzen Threadripper Pro 3000wx Series Processors
- AMD AMD Ryzen Threadripper Pro 5000 Wx-Series Processors
Published 2026-06-26. Last modified 2026-06-26.