Description
Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Published: 2026-08-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises from insufficient granularity of access control in a subsystem of Intel Xeon 6 Scalable processors that support Intel Trust Domain Extensions (TXD). The flaw permits an authorized adversary possessing an authenticated user account to access data that should be restricted, potentially leading to an information disclosure. The impact on the vulnerable system itself is listed as no direct confidentiality loss, but once the attacker gains data, the overall system confidentiality could be considered high, with no reported integrity or availability impact.

Affected Systems

Affected systems include Intel Xeon 6 Scalable processors integrated with Intel Trust Domain Extensions. The advisory does not enumerate specific firmware or microcode versions, but any system incorporating this processor family and utilizing TDX is potentially susceptible.

Risk and Exploitability

The CVSS score is 4.3, indicating a moderate base severity, while the EPSS is reported as < 1%, suggesting a very low anticipated exploitation likelihood at the time of analysis. The vulnerability is not listed in the CISA KEV catalog, further implying limited current exploitation. However, the attack requires local access and high‑complexity steps, so the likelihood remains low. Nevertheless, the potential for high‑impact confidentiality exposure warrants monitoring or mitigation as advised by Intel.

Generated by OpenCVE AI on August 12, 2026 at 21:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Intel microcode or firmware update as detailed in the Intel Security Advisory Intel‑SA‑01404.
  • Restrict privileged access to Intel Xeon processors with Intel TDX by enforcing least‑privilege policies and disabling TDX functionality on systems where it is not required.
  • Continuously monitor system logs for unauthorized memory‑read activities and anomalous local access patterns that could indicate exploitation attempts.

Generated by OpenCVE AI on August 12, 2026 at 21:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel xeon
Vendors & Products Intel
Intel xeon

Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Intel Xeon TDX Subsystem Access Control Weakness Leading to Potential Information Disclosure

Wed, 12 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Weaknesses CWE-1220
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T13:39:05.243Z

Reserved: 2025-04-15T21:18:07.401Z

Link: CVE-2025-31938

cve-icon Vulnrichment

Updated: 2026-08-12T13:39:00.417Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:43.633

Modified: 2026-08-12T20:54:11.500

Link: CVE-2025-31938

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:40:10Z

Weaknesses
  • CWE-1220

    Insufficient Granularity of Access Control