SB2023080879 - fTPM voltage fault injection attack in AMD processors
Published: August 8, 2023
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Security features bypass (CVE-ID: CVE-2023-20589)
The vulnerability allows an attacker to escalate privileges on the system.
The vulnerability exists due to the way ASP secure boot is implemented. An attacker with physical access to device can use specialized hardware to perform a voltage fault injection attack, compromise the ASP secure boot and execute arbitrary code on the system.
Remediation
Cybersecurity Help is not aware of any official remediation provided by the vendor.