Improper Initialization in UEFI Firmware for Intel Server Boards
CVE-2025-21100

5.6MEDIUM

Key Information:

Vendor

Intel

Vendor
CVE Published:
13 May 2025

What is CVE-2025-21100?

The UEFI firmware on Intel(R) Server D50DNP and M50FCP boards contains an improper initialization flaw. This vulnerability may allow a privileged user with local access to the system to potentially disclose sensitive information. It's essential for users of these server boards to review their security policies and implement necessary measures to mitigate this issue.

Affected Version(s)

Intel(R) Server D50DNP and M50FCP boards See references

References

CVSS V4

Score:
5.6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.