#VU84026 Time-of-check Time-of-use (TOCTOU) Race Condition in AMD products - CVE-2023-20521
Published: December 8, 2023
1st Gen AMD EPYC Processors
2nd Gen AMD EPYC Processors
3rd Gen AMD EPYC Processors
AMD
Description
The vulnerability allows an attacker to perform a denial of service attack.
The vulnerability exists due to a race condition in ASP Bootloader. An attacker with physical access to device can tamper with SPI ROM records after memory content verification and gain access to sensitive information of perform a denial of service (DoS) attack.