---
cve: "CVE-2023-31306"
severity: "LOW"
cvss: 3.3
epss: "12%"
vendor: "AMD"
kev: false
exploited: false
published: "2025-09-06 17:15:31"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-12T03:20:45+02:00"
---

# CVE-2023-31306

> 3.3 LOW

## Beschreibung

Improper validation of an array index in the AMD graphics driver software could allow an attacker to pass malformed arguments to the dynamic power management (DPM) functions resulting in an out of bounds read and loss of availability.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Keine | good |
| I Integrität | Keine | good |
| A Verfügbarkeit | Gering | warn |

## Referenzen

- <https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-6018.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-31306) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
