CVE-2023-20587: AMD 1st Gen AMD Epyc Processors

High severity, CVSS 7.1. EPSS: 0.2% chance of exploitation in the next 30 days.

Improper Access Control in System Management Mode (SMM) may allow an attacker access to the SPI flash potentially leading to arbitrary code execution.

Affected products

  • AMD 1st Gen AMD Epyc Processors
  • AMD 2nd Gen AMD Epyc Processors
  • AMD 3rd Gen AMD Epyc Processors
  • AMD 4th Gen AMD Epyc Processors
  • AMD AMD Epyctm Embedded 3000
  • AMD AMD Epyctm Embedded 7002
  • AMD AMD Epyctm Embedded 7003
  • AMD AMD Epyctm Embedded 9003

Published 2024-02-13. Last modified 2026-06-17.