Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2023-20572

CVE-2023-20572: AMD ASP Authentication Bypass Vulnerability

CVE-2023-20572 is an authentication bypass flaw in AMD's ASP that exploits timing discrepancies to enable brute-force attacks on HMAC. This article covers the technical details, affected systems, and mitigation strategies.

Published:

CVE-2023-20572 Overview

CVE-2023-20572 is a timing side-channel vulnerability in the AMD Secure Processor (ASP), also referred to as the Platform Security Processor. An observable timing discrepancy in the hash message authentication code (HMAC) verification path allows a privileged local attacker to conduct a brute-force attack. Successful exploitation permits the attacker to submit an arbitrary message accepted as authenticated, resulting in a loss of data integrity. The weakness is classified under [CWE-208] (Observable Timing Discrepancy). AMD documented the issue in AMD Security Bulletin #4012.

Critical Impact

A privileged local attacker can forge HMAC-authenticated messages accepted by the AMD Secure Processor, compromising the integrity of code or data validated by the ASP.

Affected Products

  • AMD Secure Processor (ASP) firmware referenced in AMD Security Bulletin #4012
  • AMD platforms relying on ASP HMAC verification for firmware or data integrity
  • Specific SKUs and firmware revisions listed by AMD in the advisory

Discovery Timeline

  • 2026-06-26 - CVE-2023-20572 published to NVD
  • 2026-06-26 - Last updated in NVD database

Technical Details for CVE-2023-20572

Vulnerability Analysis

The AMD Secure Processor validates messages using an HMAC before accepting them as authentic. The verification routine exhibits an observable timing discrepancy, meaning execution time varies with how many bytes of the computed and supplied HMAC match. An attacker who can measure this timing signal learns partial information about the correct authentication tag on each attempt. Iterating this measurement reduces the search space from a full brute force to a byte-by-byte recovery.

Because the ASP mediates trust decisions for firmware loading, secure boot, and cryptographic operations, an accepted forged message can subvert integrity guarantees that higher-level software depends on. The vulnerability requires local access and high privileges, limiting opportunistic exploitation but remaining relevant to insider threats and post-compromise escalation scenarios.

Root Cause

The root cause is a non-constant-time HMAC comparison implemented within ASP firmware. Standard byte-wise memory comparisons return on the first mismatched byte, leaking positional information through execution time. Cryptographic tag verification must instead use constant-time equality checks that always process the full tag length regardless of mismatches.

Attack Vector

Exploitation requires local access with high privileges on the host platform. The attacker submits crafted messages with candidate HMAC values to the ASP and measures response latency. By varying one byte at a time and observing timing differences, the attacker recovers the valid HMAC. Once a valid tag is derived for an arbitrary message, that message can be accepted by the ASP as authentic, breaking data integrity assurances.

No public proof-of-concept exploit is available, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. See AMD Security Bulletin #4012 for hardware and firmware specifics.

Detection Methods for CVE-2023-20572

Indicators of Compromise

  • No file-based or network indicators are published for this vulnerability, since exploitation occurs against on-die firmware over local interfaces.
  • Unexpected repeated invocations of ASP-facing interfaces from a single privileged process may indicate timing measurement attempts.
  • Firmware or microcode versions that do not match the fixed builds listed in AMD Security Bulletin #4012.

Detection Strategies

  • Inventory endpoints and servers by CPU family and ASP firmware revision to identify systems still exposed.
  • Audit privileged process activity that repeatedly interacts with ASP mailbox, SMU, or PSP driver interfaces within short intervals.
  • Correlate kernel driver loads that expose ASP command channels with subsequent bursts of authenticated message submissions.

Monitoring Recommendations

  • Track administrator and SYSTEM/root process access to platform security drivers such as amdpsp.sys and equivalent Linux kernel modules.
  • Alert on firmware version drift between platforms in the same fleet using existing configuration management telemetry.
  • Review hardware vendor firmware update logs to confirm advisory-referenced updates were applied.

How to Mitigate CVE-2023-20572

Immediate Actions Required

  • Apply the AGESA and platform firmware updates referenced in AMD Security Bulletin #4012 through your OEM or motherboard vendor.
  • Restrict local administrative access to systems that have not yet received the fixed firmware.
  • Prioritize patching on multi-tenant hosts and systems that rely on the ASP for firmware integrity or key material.

Patch Information

AMD released mitigations through updated AGESA firmware distributed by system OEMs and motherboard manufacturers. Confirm the fixed firmware version for each affected SKU in AMD Security Bulletin #4012 and apply the corresponding BIOS or UEFI update supplied by the platform vendor.

Workarounds

  • No software workaround fully eliminates the timing side channel; firmware update is the authoritative fix.
  • Limit accounts that hold administrative or kernel-mode privileges to reduce the population of actors able to invoke ASP interfaces.
  • Enforce measured boot and remote attestation policies so that unpatched platforms are visible to security operations.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.