Access Control Vulnerability in Intel Xeon Scalable Processors
CVE-2025-31938

4.3MEDIUM

What is CVE-2025-31938?

This vulnerability arises from insufficient granularity of access control in specific subsystems of some Intel Xeon Scalable processors. It may allow an authorized adversary to potentially disclose sensitive information via local access, provided they possess specific internal knowledge and execute a high-complexity attack. This attack can be initiated without user interaction, posing a risk for system confidentiality. Although there are no immediate impacts on system integrity or availability, the potential for compromised data confidentiality is significant.

Affected Version(s)

Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts. See references

References

CVSS V4

Score:
4.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.