Authentication bypass by capture-replay in RPMB protocol message authentication subsystem in Intel(R) TXE versions before 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
CVSS Vector
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIntel Trusted Execution Engine
OSIntel< 4.0.30
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
Related vulnerabilities
CVE-2020-8744HIGH7.8same product
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and ...
CVE-2020-8750HIGH7.8same product
Use after free in Kernel Mode Driver for Intel(R) TXE versions before 3.1.80 and 4.0.30 may allow an authentic...
CVE-2020-0545MEDIUM4.4same product
Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE v...
CVE-2021-45046CRITICAL9.0⚠ KEVPL ✓same vendor
Apache Log4j: niekompletna naprawa CVE-2021-44228 — RCE przez JNDI Lookup
CVE-2021-44228CRITICAL10.0⚠ KEVPL ✓same vendor
Apache Log4j2 Log4Shell — RCE przez podatną funkcję JNDI lookup