Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-35616 | Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure. |
Wed, 06 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-338 |
Tue, 13 Aug 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 13 Aug 2024 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Generation of weak and predictable Initialization Vector (IV) in PMFW (Power Management Firmware) may allow an attacker with privileges to reuse IV values to reverse-engineer debug data, potentially resulting in information disclosure. | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: AMD
Published:
Updated: 2024-11-06T15:22:36.182Z
Reserved: 2023-04-27T15:25:41.422Z
Link: CVE-2023-31305
Updated: 2024-08-13T18:27:45.575Z
Status : Deferred
Published: 2024-08-13T17:15:20.303
Modified: 2026-04-15T00:35:42.020
Link: CVE-2023-31305
No data.
OpenCVE Enrichment
No data.
EUVD