Impact
The vulnerability stems from a protection mechanism failure in Intel Data Center Attestation Primitives. An unprivileged, unauthenticated attacker can exploit the flaw with low complexity, potentially exposing sensitive data and compromising the integrity of the system. No user interaction is needed, and the attack may occur over the network with special internal knowledge, leading to downstream confidentiality impacts.
Affected Systems
Intel Data Center Attestation Primitives (Intel DCAP) is the affected product. Specific product versions are not enumerated in the available data, so all installations of Intel DCAP should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.9 indicates a high severity risk; however, the EPSS score of <1% suggests that the likelihood of exploitation remains low at present. The vulnerability is not listed in the CISA KEV catalog, but its high potential for integrity compromise warrants close attention. Attackers would likely leverage the network interface to reach DCAP, necessitating no user interaction and presenting a simple execution pathway for those with internal knowledge.
OpenCVE Enrichment