CVE-2023-20577: AMD 2nd Gen AMD Epyc Processors

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.

Affected products

  • AMD 2nd Gen AMD Epyc Processors
  • AMD 3rd Gen AMD Epyc Processors
  • AMD 4th Gen AMD Epyc Processors
  • AMD AMD Athlon 3000 Series Desktop Processors With Radeon Graphics
  • AMD AMD Athlon 3000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Epyc Embedded 3000
  • AMD AMD Epyc Embedded 7002
  • AMD AMD Epyc Embedded 7003
  • AMD AMD Epyc Embedded 9003
  • AMD AMD Instinct MI300A
  • AMD AMD Ryzen 3000 Series Desktop Processors
  • AMD AMD Ryzen 3000 Series Mobile Processor With Radeon Graphics
  • AMD AMD Ryzen 3000 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 4000 Series Desktop Processors With Radeon Graphics
  • AMD AMD Ryzen 4000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Desktop Processors
  • AMD AMD Ryzen 5000 Series Desktop Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Mobile Processors With Radeon Graphics
  • AMD AMD Ryzen 5000 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 6000 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7000 Series Processors
  • AMD AMD Ryzen 7020 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7035 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7040 Series Processors With Radeon Graphics
  • AMD AMD Ryzen 7045 Series Mobile Processors
  • and 9 more

Published 2026-09-02. Last modified 2026-09-04.