GPU VulnDB

Database/Firmware, BMC & network fabric

AMD Secure Processor secure boot - voltage fault injection (AMD-SB-4005): MULTI-TENANT ISOLATION: Voltage fault

CVE-2023-20589Firmware, BMC & network fabricfaulTPMcurated

Impact

MULTI-TENANT ISOLATION: Voltage fault injection against the ASP defeats its secure boot, yielding arbitrary code execution on the secure processor and extraction of fTPM-sealed secrets - the published work pulls BitLocker keys out. The affected list is Zen 1/2/3 **client** parts and EPYC is not on it, but the technique is the reason to read this entry: a datacenter operator with hardware in colocation, in transit, or coming back from RMA has to assume physical access to some nodes by someone.

Who can reach it

Physical access plus specialised fault-injection hardware. Not remote, not local-software.

What to do

Fixed in AGESA/PI firmware for the affected client parts - OEM BIOS package, drain and power cycle. For a server fleet the practical answer is not patching but physical control: tamper-evident handling, chain of custody for RMAs and redeployments, and not trusting fTPM-sealed secrets on any node that has left your custody. AMD's position on the server analogue (AMD-SB-3028, voltage fault injection against SEV VMs on EPYC 7272) is **WONTFIX** - physical attacks are declared outside the SEV-SNP threat model, so there is no patch coming for the server case at all.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.