CVE-2026-20901
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege.
Does this matter?
Lower severity and a low EPSS score (0.10%). Track it; it rarely justifies an emergency change on its own.
Description
Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.
- CVSS 4.0
- 4.0 MEDIUMCVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.10% probability · 1th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- intel/xeon bronze 3408u firmware · intel/xeon gold 5403n firmware · intel/xeon gold 5411n firmware · intel/xeon gold 5412u firmware · intel/xeon gold 5415\+ firmware · intel/xeon platinum 8592\+ firmware · intel/xeon platinum 8592v firmware · intel/xeon platinum 8593q firmware · intel/xeon silver 4509y firmware · intel/xeon silver 4510 firmware · intel/xeon silver 4510t firmware · intel/xeon silver 4514y firmware · intel/xeon silver 4516y\+ firmware · intel/xeon gold 5416s firmware · intel/xeon gold 5418n firmware · intel/xeon gold 5418y firmware · intel/xeon gold 5420\+ firmware · intel/xeon gold 5423n firmware · intel/xeon gold 5433n firmware · intel/xeon gold 6403n firmware · +40 more
- Source
- secure@intel.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.