CVE-2023-31323
Awaiting Analysis Awaiting Analysis - Queue

Type Confusion in AMD Secure Processor XGMI TA Causes Memory Violation

Vulnerability report for CVE-2023-31323, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-02-12

Last updated on: 2026-02-13

Assigner: Advanced Micro Devices Inc.

Description

Type confusion in the AMD Secure Processor (ASP) could allow an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA) leading to a memory safety violation potentially resulting in loss of confidentiality, integrity, or availability.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-02-12
Last Modified
2026-02-13
Generated
2026-07-26
AI Q&A
2026-02-12
EPSS Evaluated
2026-07-25
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
amd secure_processor *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-843 The product allocates or initializes a resource such as a pointer, object, or variable using one type, but it later accesses that resource using a type that is incompatible with the original type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a type confusion issue in the AMD Secure Processor (ASP). It allows an attacker to pass a malformed argument to the External Global Memory Interconnect Trusted Agent (XGMI TA), which can cause a memory safety violation.

Such a memory safety violation could lead to serious security problems including loss of confidentiality, integrity, or availability of the affected system.

Detection Guidance

I don't know

Impact Analysis

The impact of this vulnerability can be significant as it may result in loss of confidentiality, integrity, or availability of your system.

  • Loss of confidentiality means sensitive information could be exposed.
  • Loss of integrity means data or system state could be altered maliciously.
  • Loss of availability means the system or service could be disrupted or made unavailable.
Compliance Impact

I don't know

Mitigation Strategies

I don't know

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-31323. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart