Authentication Bypass Vulnerability in Intel TXE Products
CVE-2020-12355

6.8MEDIUM

Key Information:

Vendor
Intel
Vendor
CVE Published:
12 November 2020

Summary

An authentication bypass vulnerability exists in the RPMB (Replay Protected Memory Block) protocol message authentication subsystem within Intel's Trusted Execution Engine (TXE). This flaw affects versions prior to 4.0.30 and could potentially allow an unauthenticated user with physical access to exploit this vulnerability, creating an avenue for privilege escalation. This highlights the importance of ensuring that affected devices are updated to mitigate associated risks.

Affected Version(s)

Intel(R) TXE versions before 4.0.30

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.