← Vulnerability feed

Vulnerability record · CVE-2023-20593 · published 24 July 2023

CVE-2023-20593: Xen error message information leak vulnerability

Xen · Xen

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

5.5 CVSS 3.1 Medium EPSS 5.2% · top 7.8% CWE-209 · Error message information leak
5.5CVSS 3.1 base score
5.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
71Affected product versions listed by NVD
70References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

71 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://seclists.org/fulldisclosure/2023/Jul/43 Not Applicable
http://www.openwall.com/lists/oss-security/2023/07/24/3 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/1 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/12 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/13 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/14 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/15 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/16 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/17 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/5 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/6 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/26/1 Mailing ListMitigationPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/07/31/2 Mailing ListMitigationPatchThird Party Advisory
http://www.openwall.com/lists/oss-security/2023/08/08/6
http://www.openwall.com/lists/oss-security/2023/08/08/7
http://www.openwall.com/lists/oss-security/2023/08/08/8
http://www.openwall.com/lists/oss-security/2023/08/16/4
http://www.openwall.com/lists/oss-security/2023/08/16/5
http://www.openwall.com/lists/oss-security/2023/09/22/11
http://www.openwall.com/lists/oss-security/2023/09/22/9
http://www.openwall.com/lists/oss-security/2023/09/25/4
http://www.openwall.com/lists/oss-security/2023/09/25/7
http://xenbits.xen.org/xsa/advisory-433.html MitigationPatchVendor Advisory
https://cmpxchg8b.com/zenbleed.html Exploit
https://lists.debian.org/debian-lts-announce/2023/07/msg00030.html Mailing List
https://lists.debian.org/debian-lts-announce/2023/07/msg00033.html Mailing ListThird Party Advisory
https://lists.debian.org/debian-lts-announce/2023/08/msg00001.html
https://lists.fedoraproject.org/archives/list/[email protected]/message/CP6WQO3CDPLE5O635N7TAL5KC
https://lists.fedoraproject.org/archives/list/[email protected]/message/HKKYIK2EASDNUV4I7EFJKNBVO
https://lists.fedoraproject.org/archives/list/[email protected]/message/SD2G74BXS2SWOE3FIQJ6X76S3
https://security.netapp.com/advisory/ntap-20240531-0004/
https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-7008 Vendor Advisory
https://www.debian.org/security/2023/dsa-5459 Third Party Advisory
https://www.debian.org/security/2023/dsa-5461 Third Party Advisory
https://www.debian.org/security/2023/dsa-5462 Third Party Advisory
http://seclists.org/fulldisclosure/2023/Jul/43 Not Applicable
http://www.openwall.com/lists/oss-security/2023/07/24/3 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/1 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/12 Mailing List
http://www.openwall.com/lists/oss-security/2023/07/25/13 Mailing List

Track CVE-2023-20593 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20520Amd epyc 72f3 firmware out-of-bounds write vulnerabilityImproper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overrun potential…EPSS 0.79%9.8CVE-2021-26379Amd epyc 72f3 firmware vulnerabilityInsufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of i…EPSS 0.68%9.1CVE-2021-46756Amd epyc 72f3 firmware improper input validation vulnerabilityInsufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious Uapp or A…EPSS 0.65%9.1CVE-2021-46762Amd epyc 72f3 firmware improper input validation vulnerabilityInsufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.EPSS 0.35%8.8CVE-2021-46769Amd epyc 72f3 firmware improper input validation vulnerabilityInsufficient syscall input validation in the ASP Bootloader may allow a privileged attacker to execute arbitrary DMA copies, which can lead to code e…EPSS 0.78%8.4CVE-2021-26340Amd epyc 7001 firmware vulnerabilityA malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside…EPSS 0.24%8.2CVE-2021-26344Amd epyc 7203 firmware out-of-bounds write vulnerabilityAn out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the B…EPSS 0.16%7.8CVE-2021-26398Amd epyc 7h12 firmware out-of-bounds write vulnerabilityInsufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure…EPSS 0.21%

Source: NIST National Vulnerability Database (record CVE-2023-20593), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.