CVE-2023-20572
Received Received - Intake
Timing Discrepancy in AMD ASP Allows Brute-Force Attack

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Advanced Micro Devices Inc.

Description
An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary message, potentially leading to a loss of data integrity.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-208 Two separate operations in a product require different amounts of time to complete, in a way that is observable to an actor and reveals security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability involves an observable timing discrepancy in the ASP that can be exploited by a privileged attacker. The attacker can use this timing difference to perform a brute-force attack against the hash message authentication code (HMAC). Successfully doing so allows the attacker to input an arbitrary message.

The consequence of this is a potential loss of data integrity, meaning that the data could be altered or tampered with without detection.

Impact Analysis

This vulnerability can impact you by allowing a privileged attacker to compromise the integrity of your data. By exploiting the timing discrepancy, the attacker could manipulate or forge messages, leading to unauthorized data modification.

Such a loss of data integrity can undermine trust in the system, cause incorrect system behavior, or lead to further security breaches.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-20572. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart