云虫漏洞库

CVE-2026-20901 - Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and - 漏洞详情

漏洞编号:CVE-2026-20901

风险等级:中危

漏洞来源:CVE

CVE 编号:CVE-2026-20901

CNNVD 编号:-

厂商/产品:intel / xeon_bronze_3408u_firmware

影响范围:cpe:2.3:o:intel:xeon_bronze_3408u_firmware:-:*:*:*:*:*:*:*

CWE:CWE-20

发布/更新时间:2026-08-11 / 2026-08-28

漏洞描述

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.

相关链接

相关漏洞

« 返回首页