CVE-2020-12355

MEDIUM

Intel Trusted Execution Engine < 4.0.30 - Authentication Bypass

Title source: rule
STIX 2.1

Description

Authentication bypass by capture-replay in RPMB protocol message authentication subsystem in Intel(R) TXE versions before 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Scores

CVSS v3 6.8
EPSS 0.0013
EPSS Percentile 31.7%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-294
Status published
Products (1)
intel/trusted_execution_engine < 4.0.30
Published Nov 12, 2020
Tracked Since Feb 18, 2026