Junglewise Threat Intelligence

CVE-2023-20576: AMD AGESA insufficient verification of data authenticity in SPI ROM

CVE-2023-20576 · Severity: high · CVSS 7.7 · Published 2026-09-02

Vendors: Amd.

Executive brief

AMD AGESA is firmware used to initialize and configure processors. Insufficient verification of SPI ROM data allows attackers to modify firmware, leading to denial of service or privilege escalation that compromises system integrity and control.

Technical details

This vulnerability is an insufficient data authenticity verification flaw in AMD AGESA firmware. The root cause is inadequate validation of SPI ROM data before use, allowing an attacker with physical or elevated local access to modify firmware without detection. An attacker can update SPI ROM contents to execute malicious code or corrupt critical firmware functionality, resulting in denial of service or privilege escalation depending on execution context. Patches are expected to be available from AMD through official security bulletins.

Affected products

  • AMD AGESA <UNKNOWN>

Timeline

  • 2026-09-02: disclosed
  • 2026-09-02: advisory: AMD security bulletin SB-7009

References

Related threats