CVE-2023-31313 Details
Description
An unintended proxy or intermediary in the AMD power management firmware (PMFW) could allow a privileged attacker to send malformed messages to the system management unit (SMU) potentially resulting in arbitrary code execution.
A vulnerability exists in the AMD power management firmware (PMFW) that could allow a privileged attacker to send malformed messages to the system management unit (SMU). This unintended proxy or intermediary could potentially lead to arbitrary code execution.
Users can update to the AMD Software: Adrenalin Edition 25.6.1 (25.10.01.09) or AMD Software: PRO Edition 25.Q2 (25.10.10). For AMD Radeon™ PRO V710 series graphics products, this vulnerability is included in the AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01) release.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 12, 2026CISA-ADP
Assessed Feb 12, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6024.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-441 | Unintended Proxy or Intermediary ('Confused Deputy') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| AMD Instinct MI210 | All versions |
CPE
Remediation
| |
| AMD Instinct MI250 | All versions |
CPE
Remediation
| |
| AMD Instinct MI300A | All versions |
CPE
Remediation
| |
| AMD Instinct MI300X | All versions |
CPE
Remediation
| |
| AMD Instinct MI308X | All versions |
CPE
Remediation
| |
| AMD Instinct MI325X | All versions |
CPE
Remediation
| |
| AMD Radeon PRO V520 | All versions |
CPE
Remediation
| |
| AMD Radeon PRO V620 | All versions |
CPE
Remediation
| |
| AMD Radeon PRO V710 | All versions |
CPE
Remediation
| |
| AMD Radeon PRO W5000 | All versions |
CPE
Remediation
| |
| AMD Radeon PRO W6000 | All versions |
CPE
Remediation
| |
| AMD Radeon PRO W7000 | All versions |
CPE
Remediation
| |
| AMD Radeon PRO WX 8000 | All versions |
CPE
Remediation
| |
| AMD Radeon PRO VII | All versions |
CPE
Remediation
| |
| AMD Radeon RX 5000 | All versions |
CPE
Remediation
| |
| AMD Radeon RX 6000 | All versions |
CPE
Remediation
| |
| AMD Radeon RX 7000 | All versions |
CPE
Remediation
| |
| AMD Radeon RX 9000 | All versions |
CPE
Remediation
| |
| AMD Radeon AI PRO 9000 | All versions |
CPE
Remediation
| |
| AMD Radeon RX Vega | All versions |
CPE
Remediation
| |
| AMD Radeon VII | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 8000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded 9000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded R1000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded R2000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded V1000 | All versions |
CPE
Remediation
| |
| AMD Ryzen Embedded V2000 | All versions |
CPE
Remediation
| |
| AMD Athlon 3000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 4000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 5000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 7000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 8000 | All versions |
CPE
Remediation
| |
| AMD Ryzen 9000 | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Feb 12, 2026 | New CVE Received | [email protected] |
Volerion