PT-2020-4742 · Intel · Intel Txe

Published

2020-11-10

·

Updated

2025-11-04

·

CVE-2020-12355

CVSS v3.1

6.8

Medium

VectorAV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Intel TXE versions prior to 4.0.30
Description: The issue is related to insufficient authentication in the RPMB protocol message authentication subsystem of Intel Trusted Execution Engine (TXE) firmware. It may allow an attacker to bypass authentication through capture-replay, potentially enabling privilege escalation via physical access.
Recommendations: For Intel TXE versions prior to 4.0.30, update to version 4.0.30 or later to resolve the issue.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-05294
CVE-2020-12355

Affected Products

Intel Txe