AMD Zenbleed Vulnerability - BIOS version update needed in Acer Swift 3 models such as SF314-43

Options
msander452
msander452 Member Posts: 19

Tinkerer

edited June 15 in Swift and Spin Series

Some Acer Swift 3 models such as SF314-43 come with AMD Ryzen 5 (other models using AMD CPUs based on Zen 2 architecture are also affected).

This CPU is affected by Zenbleed Vulnerability which posses security risk to users (possibility of attacker stealing passwords, credit card numbers and other data or credentials) .

Acer - please release new BIOS and update AGESA firmware to version Cezanne PI FP6 1.0.1.0 to fix the following HIGH SEVERITY and MEDIUM SEVERITY issues:


CVE-2023-20563 - High Severity

CVE-2023-20565 - High Severity

CVE-2023-20571 - Medium Severity

CVE-2023-20593 - Medium Severity

please refer to :

https://www.amd.com/en/resources/product-security/bulletin/amd-sb-4002.html

https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7008.html

[Edited the thread to add model number to the title]

Answers

  • Puraw
    Puraw ACE, Member Posts: 9,572 Trailblazer
    Options

    Make sure your system is fully up to date with BOIS version 1.08 and Windows11 23H2 version 22631.3672, have all W11 security enabled (picture) with green dots, you don't need to worry about core vulnerabilities, Microsoft provides the best security, I recommend you uninstall 3rd-party anti-virus programs as these clash with the Windows Firewall/Defender, AV programs require proprietary uninstallers that you can download from their websites, Windows uninstaller will not completely of fail uninstalling 3rd-party AV programs.

  • msander452
    msander452 Member Posts: 19

    Tinkerer

    Options

    It looks like you did not investigate the problem carefully. The last BIOS (v.1.08) does not fix Zenbleed vulnerability of AMD Ryzen™ 5 5500U. The BIOS release notes mention that this BIOS version updates AGESA firmware to PI FP6_1.0.0.C but  in order to fix the Zenbleed vulnerability for this particular CPU, AGESA firmware needs to be updated to version Cezanne PI FP6 1.0.1.0.

    ACER needs to release new BIOS update for this laptop model Swift 3 SF314-43 and the BIOS update needs to upgrade Cezanne PI FP6 to version 1.0.1.0.

    Currently this model is still vulnerable to all High and Medium Severity security issues that I have mentioned in my original post. Anyone who thinks about buying this laptop model should think twice and put his plans on hold until ACER fixes all security problems of this device.

  • msander452
    msander452 Member Posts: 19

    Tinkerer

    Options

    It seems like you haven't carefully investigated the issue that I described.

    The BIOS v1.08 does not fix the Zenbleed vulnerability of Acer Swift 3 SF314-43.

    The BIOS v1.08 release notes mention that this BIOS version updates AGESA firmware to PI FP6_1.0.0.C but  in order to fix the Zenbleed
    vulnerability for this particular CPU, AGESA firmware needs to be updated to version Cezanne PI FP6 1.0.1.0.

    ACER needs to release new BIOS update that will fix this security issue by upgrading Cezanne PI FP6 to version 1.0.1.0.

    The CPU of this laptop is still vulnerable to all the security problems I listed in my first post and anyone thinking about buying this model should think twice and put his plans on hold at least until the security problems of this laptop will be fixed by new BIOS version that will be released by ACER.

  • msander452
    msander452 Member Posts: 19

    Tinkerer

    Options

    It seems like you haven't carefully investigated the issue that I had described.


    The BIOS v1.08 does not fix the Zenbleed vulnerability of Acer Swift 3 SF314-43.


    The BIOS v1.08 release notes mention that this BIOS version updates AGESA firmware to PI FP6_1.0.0.C but  in order to fix the Zenbleed
    vulnerability for this particular CPU, AGESA firmware needs to be updated to version Cezanne PI FP6 1.0.1.0.


    ACER needs to release new BIOS update that will fix this security issue by upgrading Cezanne PI FP6 to version 1.0.1.0.

    The CPU of this laptop is still vulnerable to all the security problems I listed in my first post and anyone thinking about buying this model should think twice and put his plans on hold at least until the security problems of this laptop will be fixed by new BIOS version that will be released by ACER.

  • jonna241
    jonna241 Member Posts: 4 New User
    Options

    Is there any update on this? When will ACER release new bios for swift 3 to fix this issue? Unfortunately I have bought this particular model. From what I can see, all other manufacturers have already released updated BIOS to fix AMD cpu bug… why does it take so long for ACER to fix this???

  • billsey
    billsey ACE Posts: 32,277 Trailblazer
    Options

    You will have to ask Acer, none of us users will have any real insight into when they might release that. As stated above, the Intel updates come in via Windows update, but apparently Microsoft isn't doing that for the AMD updates.

    Click on "Like" if you find my answer useful or click on "Yes" if it answers your question.