Junglewise Threat Intelligence

CVE-2023-20572: AMD Secure Processor timing discrepancy in HMAC verification

CVE-2023-20572 · Severity: info · CVSS 5.6 · Published 2026-06-26

Vendors: Amd.

Executive brief

A security vulnerability exists in the AMD Secure Processor (ASP), a dedicated security chip within many AMD processors that handles sensitive tasks like encryption and system boot security. A highly privileged attacker with local access could exploit a timing flaw to bypass certain security checks. This could allow them to tamper with system data or messages, potentially compromising the integrity of the device's security operations.

Technical details

This vulnerability is classified as an observable timing discrepancy (CWE-208) within the AMD Secure Processor (ASP). The flaw allows a local attacker with high privileges to measure the time taken for HMAC verification, enabling a brute-force attack to guess the correct authentication code. If successful, the attacker can input arbitrary messages that the system will accept as valid, leading to a loss of data integrity. The attack requires high privileges and local access, and it is mitigated by updating to the specific AGESA firmware versions listed in the AMD security bulletin.

Affected products

  • AMD Athlon 3000 Series Mobile Processors with Radeon Graphics Picasso-FP5 prior to 1.0.1.1, Pollock-FT5 prior to 1.0.0.7
  • AMD Ryzen 5000 Series Processors with Radeon Graphics Cezanne-FP6 prior to 1.0.1.0
  • AMD Ryzen 7030 Series Mobile processors with Radeon Graphics Cezanne-FP6 prior to 1.0.1.0
  • AMD Ryzen 4000 Series Mobile Processors with Radeon Graphics Renoir-FP6 prior to 1.0.0.D
  • AMD Ryzen 6000 Series Processors with Radeon Graphics Rembrandt-FP7 prior to 1.0.0.A
  • AMD Ryzen 7020 Series Processors with Radeon Graphics MendocinoPI-FT6 prior to 1.0.0.6
  • AMD Ryzen 5000 Series Desktop Processors ComboAM4v2PI prior to 1.2.0.CA

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References

Related threats