Junglewise Threat Intelligence

CVE-2023-31309: AMD Power Management Firmware improper validation in PMFW

CVE-2023-31309 · Severity: info · CVSS 6.8 · Published 2026-05-15

Vendors: Amd.

Executive brief

A vulnerability in AMD's Power Management Firmware could allow a high-privileged user to provide malformed data during internal system operations. This could lead to the unauthorized viewing of sensitive information or cause system instability. An attacker would already need significant administrative control over the system to exploit this flaw.

Technical details

An improper validation of array index (CWE-129) exists in the AMD Power Management Firmware (PMFW). A local attacker with high privileges can pass malformed workload arguments when the system exports table data from the System Management Unit (SMU) to the DRAM. This improper validation can be leveraged to access sensitive memory or cause a denial-of-service condition. The vulnerability requires high privileges (PR:H) and local access (AV:L) to exploit.

Affected products

  • AMD Power Management Firmware (PMFW)

Timeline

  • 2026-05-15: disclosed: Initial NVD publication date

References

Related threats