CVE-2023-20540
Received Received - Intake
Timing Discrepancy in ASP Allows Brute-Force Attack

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Advanced Micro Devices Inc.

Description
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing arbitrary message input, potentially leading to a loss of data integrity.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves an observable timing discrepancy in the ASP (presumably a software component) that could allow a privileged attacker to perform a brute-force attack against the hash message authentication code (HMAC).

By exploiting this timing difference, the attacker could input arbitrary messages and potentially compromise the integrity of the data.

Impact Analysis

The vulnerability could lead to a loss of data integrity because an attacker might be able to manipulate or forge messages by exploiting the timing discrepancy to brute-force the HMAC.

This means that trusted data could be altered or corrupted without detection, potentially affecting the reliability and security of systems relying on this component.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-20540. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart