Back to Database
Status published
High
CVE-2022-23829
A potential weakness in AMD SPI protection features may allow...
Vulnerability Description
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-23829
Credits & Attribution
No credits recorded in the NVD database.
More from AMD
View All →CVE-2025-66664
Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC...
Medium
4.6
CVE-2025-66660
Insufficient parameter sanitization in TEE SOC Driver could allow an...
Low
1.8
CVE-2025-62628
Unsafe OpenSSL initialization within some AMD optional tools may allow...
High
7
CVE-2025-62627
An untrusted pointer dereference in the ionic cloud driver for...
High
7.2
CVE-2025-62626
Improper handling of insufficient entropy in the AMD CPUs could...
High
7.2
Affected Vendor
Affected Software
AMD Ryzen™ Threadripper™ PRO Processors 5900 WX-Series, AMD Ryzen™ 6000 Series Mobile Processors and Workstations, AMD Ryzen™ 7000 Series Desktop Processors, AMD Ryzen™ 5000 Series Mobile Processors, AMD Ryzen™ 5000 Series Desktop Processors, AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 3000 Series Desktop Processors, AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics, AMD Ryzen™ 4000 Series Mobile Processors, AMD Ryzen™ 3000 Series Mobile Processor / 2nd Gen AMD Ryzen™ Mobile Processor with Radeon™ Graphics, AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ Threadripper™ PRO Processor, 1st Gen AMD EPYC™ Processors, 2nd Gen AMD EPYC™ Processors, 3rd Gen AMD EPYC™ Processors, AMD EPYC™ Embedded 3000, AMD EPYC (TM) Embedded 7002, AMD EPYC™ Embedded 7003, AMD RyzenTM Embedded R1000, AMD RyzenTM Embedded R2000, AMD RyzenTM Embedded 5000, AMD RyzenTM Embedded V1000, AMD RyzenTM Embedded V2000, AMD RyzenTM Embedded V3000
Vulnerable Versions:
various
Timeline
Official Publish:
June 18th, 2024
Last Modified:
August 29th, 2024
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.