PT-2026-21012 · Advanced Micro Devices Inc.+1 · Amd Ryzen™ Embedded 5000+5

CVE-2023-20540

·

Published

2026-02-10

·

Updated

2026-06-26

CVSS v2.0

5.0

Medium

VectorAV:L/AC:H/Au:S/C:P/I:P/A:C
Name of the Vulnerable Software and Affected Versions AMD Secure Processor (affected versions not specified)
Description A timing discrepancy in the ASP and unreliable pointer dereferencing in the AMD Secure Processor firmware for GPUs allow a privileged attacker to perform a brute-force attack against the hash message authentication code. This could enable arbitrary message input and the bypass of existing security restrictions, potentially leading to a loss of data integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Untrusted Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-01986
CVE-2023-20540

Affected Products

Amd Ryzen™ Embedded 5000
Amd Ryzen™ Embedded V2000
Amd Ryzen™ 3000 Series Desktop Processors
Amd Ryzen™ 5000 Series Desktop Processors
Amd Ryzen™ Threadripper™ 3000 Series Processors
Amd Ryzen™ Threadripper™ Pro 5000Wx Processors