CVE Feed

    Dashboard / CVE / CVE-2023-31307

    CVE-2023-31307

    Improper validation of array index in Power Management Firmware (PMFW) may allow a privileged attacker to cause an out-of-bounds memory read within PMFW, potentially leading to a denial of service.

    Published:Aug 13, 2024
    Last Modified:Dec 13, 2024
    EPS:Aug 13, 2024
    EPSS Score:0.00035
    CVSS Score:2.3

    Affected Products

    Vendor
    Amd
    Product
    Radeon Pro W6300
    Vendor
    Amd
    Product
    Radeon Pro W6400
    Vendor
    Amd
    Product
    Radeon Pro W6600
    Vendor
    Amd
    Product
    Radeon Pro W6800
    Vendor
    Amd
    Product
    Radeon Rx 6300m
    Vendor
    Amd
    Product
    Radeon Rx 6400
    Vendor
    Amd
    Product
    Radeon Rx 6450m
    Vendor
    Amd
    Product
    Radeon Rx 6500 Xt
    Vendor
    Amd
    Product
    Radeon Rx 6500m
    Vendor
    Amd
    Product
    Radeon Rx 6550m
    Vendor
    Amd
    Product
    Radeon Rx 6550s
    Vendor
    Amd
    Product
    Radeon Rx 6600
    Vendor
    Amd
    Product
    Radeon Rx 6600 Xt
    Vendor
    Amd
    Product
    Radeon Rx 6600m
    Vendor
    Amd
    Product
    Radeon Rx 6600s
    Vendor
    Amd
    Product
    Radeon Rx 6650 Xt
    Vendor
    Amd
    Product
    Radeon Rx 6650m
    Vendor
    Amd
    Product
    Radeon Rx 6650m Xt
    Vendor
    Amd
    Product
    Radeon Rx 6700
    Vendor
    Amd
    Product
    Radeon Rx 6700 Xt
    Vendor
    Amd
    Product
    Radeon Rx 6700m
    Vendor
    Amd
    Product
    Radeon Rx 6700s
    Vendor
    Amd
    Product
    Radeon Rx 6750 Gre
    Vendor
    Amd
    Product
    Radeon Rx 6750 Xt
    Vendor
    Amd
    Product
    Radeon Rx 6800
    Vendor
    Amd
    Product
    Radeon Rx 6800 Xt
    Vendor
    Amd
    Product
    Radeon Rx 6800m
    Vendor
    Amd
    Product
    Radeon Rx 6800s
    Vendor
    Amd
    Product
    Radeon Rx 6850m Xt
    Vendor
    Amd
    Product
    Radeon Rx 6900 Xt
    Vendor
    Amd
    Product
    Radeon Rx 6950 Xt
    Vendor
    Amd
    Product
    Radeon Software

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High