Aller au contenu

Fiche vulnérabilité

CVE-2026-20901 : faille moyenne intel xeon bronze 3408u firmware (CVSS 5.3)

Description

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.

En bref

Sévérité
Moyenne (CVSS 5.3)
Vecteur CVSS
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:N/I:H/A:N
Exploitation active
Non signalée par la CISA
Publication
11 août 2026
Dernière mise à jour
28 août 2026

Produits concernés

  • intel xeon bronze 3408u firmware
  • intel xeon gold 5403n firmware
  • intel xeon gold 5411n firmware
  • intel xeon gold 5412u firmware
  • intel xeon gold 5415\+ firmware
  • intel xeon platinum 8592\+ firmware
  • intel xeon platinum 8592v firmware
  • intel xeon platinum 8593q firmware
  • intel xeon silver 4509y firmware
  • intel xeon silver 4510 firmware
  • intel xeon silver 4510t firmware
  • intel xeon silver 4514y firmware
  • intel xeon silver 4516y\+ firmware
  • intel xeon gold 5416s firmware
  • intel xeon gold 5418n firmware
  • intel xeon gold 5418y firmware
  • intel xeon gold 5420\+ firmware
  • intel xeon gold 5423n firmware
  • intel xeon gold 5433n firmware
  • intel xeon gold 6403n firmware

Références

Rechercher une autre vulnérabilité dans la base CVE