Description

Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.

INFO

Published Date :

Feb. 13, 2024, 6:15 p.m.

Last Modified :

Oct. 17, 2024, 2:34 p.m.

Remotely Exploitable :

No

Impact Score :

1.4

Exploitability Score :

1.8
Public PoC/Exploit Available at Github

CVE-2023-20570 has a 1 public PoC/Exploit available at Github. Go to the Public Exploits tab to see the list.

Affected Products

The following products are affected by CVE-2023-20570 vulnerability. Even if cvefeed.io is aware of the exact versions of the products that are affected, the information is not represented in the table below.

ID Vendor Product Action
1 Amd alveo_u50_firmware
2 Amd alveo_u50
3 Amd alveo_u200_firmware
4 Amd alveo_u200
5 Amd alveo_u250_firmware
6 Amd alveo_u250
7 Amd alveo_u280_firmware
8 Amd alveo_u280
9 Amd kintex_ultrascale\+_ku3p_firmware
10 Amd kintex_ultrascale\+_ku3p
11 Amd kintex_ultrascale\+_ku5p_firmware
12 Amd kintex_ultrascale\+_ku5p
13 Amd kintex_ultrascale\+_ku9p_firmware
14 Amd kintex_ultrascale\+_ku9p
15 Amd kintex_ultrascale\+_ku11p_firmware
16 Amd kintex_ultrascale\+_ku11p
17 Amd kintex_ultrascale\+_ku13p_firmware
18 Amd kintex_ultrascale\+_ku13p
19 Amd kintex_ultrascale\+_ku15p_firmware
20 Amd kintex_ultrascale\+_ku15p
21 Amd kintex_ultrascale\+_ku19p_firmware
22 Amd kintex_ultrascale\+_ku19p
23 Amd kintex_ultrascale_ku025_firmware
24 Amd kintex_ultrascale_ku025
25 Amd kintex_ultrascale_ku035_firmware
26 Amd kintex_ultrascale_ku035
27 Amd kintex_ultrascale_ku040_firmware
28 Amd kintex_ultrascale_ku040
29 Amd kintex_ultrascale_ku060_firmware
30 Amd kintex_ultrascale_ku060
31 Amd kintex_ultrascale_ku085_firmware
32 Amd kintex_ultrascale_ku085
33 Amd kintex_ultrascale_ku095_firmware
34 Amd kintex_ultrascale_ku095
35 Amd kintex_ultrascale_ku115_firmware
36 Amd kintex_ultrascale_ku115
37 Amd virtex_ultrascale_xcvu065_firmware
38 Amd virtex_ultrascale_xcvu065
39 Amd virtex_ultrascale_xcvu080_firmware
40 Amd virtex_ultrascale_xcvu080
41 Amd virtex_ultrascale_xcvu095_firmware
42 Amd virtex_ultrascale_xcvu095
43 Amd virtex_ultrascale_xcvu125_firmware
44 Amd virtex_ultrascale_xcvu125
45 Amd virtex_ultrascale_xcvu160_firmware
46 Amd virtex_ultrascale_xcvu160
47 Amd virtex_ultrascale_xcvu190_firmware
48 Amd virtex_ultrascale_xcvu190
49 Amd virtex_ultrascale_xcvu440_firmware
50 Amd virtex_ultrascale_xcvu440
51 Amd virtex_ultrascale\+_vu3p_firmware
52 Amd virtex_ultrascale\+_vu3p
53 Amd virtex_ultrascale\+_vu5p_firmware
54 Amd virtex_ultrascale\+_vu5p
55 Amd virtex_ultrascale\+_vu7p_firmware
56 Amd virtex_ultrascale\+_vu7p
57 Amd virtex_ultrascale\+_vu9p_firmware
58 Amd virtex_ultrascale\+_vu9p
59 Amd virtex_ultrascale\+_vu11p_firmware
60 Amd virtex_ultrascale\+_vu11p
61 Amd virtex_ultrascale\+_vu13p_firmware
62 Amd virtex_ultrascale\+_vu13p
63 Amd virtex_ultrascale\+_vu19p_firmware
64 Amd virtex_ultrascale\+_vu19p
65 Amd virtex_ultrascale\+_vu23p_firmware
66 Amd virtex_ultrascale\+_vu23p
67 Amd virtex_ultrascale\+_vu27p_firmware
68 Amd virtex_ultrascale\+_vu27p
69 Amd virtex_ultrascale\+_vu29p_firmware
70 Amd virtex_ultrascale\+_vu29p
71 Amd virtex_ultrascale\+_vu31p_firmware
72 Amd virtex_ultrascale\+_vu31p
73 Amd virtex_ultrascale\+_vu33p_firmware
74 Amd virtex_ultrascale\+_vu33p
75 Amd virtex_ultrascale\+_vu35p_firmware
76 Amd virtex_ultrascale\+_vu35p
77 Amd virtex_ultrascale\+_vu37p_firmware
78 Amd virtex_ultrascale\+_vu37p
79 Amd virtex_ultrascale\+_vu45p_firmware
80 Amd virtex_ultrascale\+_vu45p
81 Amd virtex_ultrascale\+_vu47p_firmware
82 Amd virtex_ultrascale\+_vu47p
83 Amd virtex_ultrascale\+_vu57p_firmware
84 Amd virtex_ultrascale\+_vu57p
85 Amd artix_ultrascale\+_au7p_firmware
86 Amd artix_ultrascale\+_au7p
87 Amd artix_ultrascale\+_au10p_firmware
88 Amd artix_ultrascale\+_au10p
89 Amd artix_ultrascale\+_au15p_firmware
90 Amd artix_ultrascale\+_au15p
91 Amd artix_ultrascale\+_au20p_firmware
92 Amd artix_ultrascale\+_au20p
93 Amd artix_ultrascale\+_au25p_firmware
94 Amd artix_ultrascale\+_au25p
References to Advisories, Solutions, and Tools

Here, you will find a curated list of external links that provide in-depth information, practical solutions, and valuable tools related to CVE-2023-20570.

URL Resource
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8002.html Vendor Advisory

We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).

ConFuzz is an advanced FPGA configuration engine fuzzing and rapid prototyping framework based on boofuzz and OpenOCD.

Python Shell

Updated: 2 months, 2 weeks ago
12 stars 3 fork 3 watcher
Born at : Jan. 15, 2024, 7:14 a.m. This repo has been linked 1 different CVEs too.

Results are limited to the first 15 repositories due to potential performance issues.

The following list is the news that have been mention CVE-2023-20570 vulnerability anywhere in the article.

The following table lists the changes that have been made to the CVE-2023-20570 vulnerability over time.

Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.

  • Initial Analysis by [email protected]

    Oct. 17, 2024

    Action Type Old Value New Value
    Added CVSS V3.1 NIST AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
    Changed Reference Type https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8002.html No Types Assigned https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8002.html Vendor Advisory
    Added CWE NIST CWE-345
    Added CPE Configuration AND OR *cpe:2.3:o:amd:alveo_u50_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:alveo_u50:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:alveo_u200_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:alveo_u200:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:alveo_u250_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:alveo_u250:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:alveo_u280_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:alveo_u280:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale\+_ku3p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale\+_ku3p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale\+_ku5p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale\+_ku5p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale\+_ku9p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale\+_ku9p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale\+_ku11p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale\+_ku11p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale\+_ku13p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale\+_ku13p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale\+_ku15p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale\+_ku15p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale\+_ku19p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale\+_ku19p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale_ku025_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale_ku025:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale_ku035_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale_ku035:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale_ku040_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale_ku040:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale_ku060_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale_ku060:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale_ku085_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale_ku085:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale_ku095_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale_ku095:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:kintex_ultrascale_ku115_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:kintex_ultrascale_ku115:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale_xcvu065_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale_xcvu065:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale_xcvu080_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale_xcvu080:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale_xcvu095_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale_xcvu095:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale_xcvu125_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale_xcvu125:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale_xcvu160_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale_xcvu160:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale_xcvu190_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale_xcvu190:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale_xcvu440_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale_xcvu440:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu3p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu3p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu5p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu5p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu7p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu7p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu9p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu9p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu11p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu11p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu13p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu13p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu19p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu19p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu23p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu23p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu27p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu27p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu29p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu29p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu31p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu31p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu33p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu33p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu35p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu35p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu37p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu37p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu45p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu45p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu47p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu47p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:virtex_ultrascale\+_vu57p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:virtex_ultrascale\+_vu57p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:artix_ultrascale\+_au7p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:artix_ultrascale\+_au7p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:artix_ultrascale\+_au10p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:artix_ultrascale\+_au10p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:artix_ultrascale\+_au15p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:artix_ultrascale\+_au15p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:artix_ultrascale\+_au20p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:artix_ultrascale\+_au20p:-:*:*:*:*:*:*:*
    Added CPE Configuration AND OR *cpe:2.3:o:amd:artix_ultrascale\+_au25p_firmware:-:*:*:*:*:*:*:* OR cpe:2.3:h:amd:artix_ultrascale\+_au25p:-:*:*:*:*:*:*:*
  • CVE Modified by [email protected]

    May. 14, 2024

    Action Type Old Value New Value
  • CVE Received by [email protected]

    Feb. 13, 2024

    Action Type Old Value New Value
    Added Description Insufficient verification of data authenticity in the configuration state machine may allow a local attacker to potentially load arbitrary bitstreams.
    Added Reference Advanced Micro Devices Inc. https://www.amd.com/en/resources/product-security/bulletin/amd-sb-8002.html [No types assigned]
EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days. Following chart shows the EPSS score history of the vulnerability.
CWE - Common Weakness Enumeration

While CVE identifies specific instances of vulnerabilities, CWE categorizes the common flaws or weaknesses that can lead to vulnerabilities. CVE-2023-20570 is associated with the following CWEs:

Exploit Prediction

EPSS is a daily estimate of the probability of exploitation activity being observed over the next 30 days.

0.04 }} 0.00%

score

0.06690

percentile

CVSS31 - Vulnerability Scoring System
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability