SB2023080205 - Software-based power side-channel attack on AMD CPUs
Published: August 2, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper restriction of software interfaces to hardware features (CVE-ID: CVE-2023-20583)
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to the way data in a cache line changes over time. A local user can monitor the CPU power consumption and potentially gain access to sensitive information using software-based power side channels.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.