Improper Input Validation in UEFI Firmware for Intel Server Boards
CVE-2025-20009
5.6MEDIUM
Key Information:
- Vendor
Intel
- Vendor
- CVE Published:
- 13 May 2025
What is CVE-2025-20009?
A vulnerability has been identified in the UEFI firmware GenerationSetup module for Intel Server D50DNP and M50FCP boards. This issue stems from improper input validation, which may allow a privileged user to disclose sensitive information through local access. It is crucial for organizations to assess their systems for exposure and manage configurations accordingly to prevent potential data breaches.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Intel(R) Server D50DNP and M50FCP boards See references
References
CVSS V4
Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved