CVE-2020-12890

Improper handling of pointers in the System Management Mode (SMM) handling code may allow for a privileged attacker with physical or administrative access to potentially manipulate the AMD Generic Encapsulated Software Architecture (AGESA) to execute arbitrary code undetected by the operating system.
References
Configurations

Configuration 1 (hide)

cpe:2.3:o:amd:amd_generic_encapsulated_software_architecture:-:*:*:*:*:*:*:*

History

15 Dec 2021, 20:01

Type Values Removed Values Added
CWE NVD-CWE-noinfo
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 6.7
References (MISC) https://www.amd.com/en/corporate/product-security - (MISC) https://www.amd.com/en/corporate/product-security - Vendor Advisory
CPE cpe:2.3:o:amd:amd_generic_encapsulated_software_architecture:-:*:*:*:*:*:*:*

10 Dec 2021, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-10 22:15

Updated : 2023-12-10 14:09


NVD link : CVE-2020-12890

Mitre link : CVE-2020-12890

CVE.ORG link : CVE-2020-12890


JSON object : View

Products Affected

amd

  • amd_generic_encapsulated_software_architecture