Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-20709

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 6.6
EPSS Низкий

Описание

Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via physical access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

A flaw was found in some Intel Pentium Processor Silver Series, Intel Celeron Processor J Series, and Intel Celeron Processor N Series. This vulnerability arises from the use of a default cryptographic key in the hardware. A sophisticated attacker with physical access and privileged user access could exploit this to achieve an escalation of privilege, potentially compromising the system's confidentiality and integrity.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10microcode_ctlFix deferred
Red Hat Enterprise Linux 6microcode_ctlFix deferred
Red Hat Enterprise Linux 7microcode_ctlFix deferred
Red Hat Enterprise Linux 8microcode_ctlFix deferred
Red Hat Enterprise Linux 9microcode_ctlFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1392
https://bugzilla.redhat.com/show_bug.cgi?id=2456637microcode_ctl: Intel Processors: Escalation of privilege due to default cryptographic key

EPSS

Процентиль: 2%
0.00111
Низкий

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
nvd
4 месяца назад

Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via physical access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

CVSS3: 6.6
github
4 месяца назад

Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via physical access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

EPSS

Процентиль: 2%
0.00111
Низкий

6.6 Medium

CVSS3