CVE-2025-31938
Awaiting Analysis Awaiting Analysis - Queue

Insufficient Access Control in Intel Xeon 6 Scalable Processors

Vulnerability report for CVE-2025-31938, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-12

Assigner: Intel Corporation

Description

Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-12
Generated
2026-09-01
AI Q&A
2026-08-11
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
intel xeon_6_scalable_processors *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1220 The product implements access controls via a policy or other feature with the intention to disable or restrict accesses (reads and/or writes) to assets in a system from untrusted agents. However, implemented access controls lack required granularity, which renders the control policy too broad because it allows accesses from unauthorized agents to the security-sensitive assets.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves insufficient granularity of access control in some subsystem for certain Intel Xeon 6 Scalable processors with Intel TDX. It may allow an authorized adversary with authenticated user access and high complexity attack methods to disclose data. The attack requires local access, special internal knowledge, and no user interaction.

Detection Guidance

This vulnerability cannot be directly detected through standard commands due to its high complexity and specialized internal knowledge requirements. Intel recommends checking for updated microcode or firmware versions from your hardware vendor to confirm mitigation.

Impact Analysis

The vulnerability could lead to data exposure, potentially compromising sensitive information. However, it requires specific conditions like local access, authenticated user status, and high complexity attack methods, making it difficult to exploit.

Compliance Impact

This vulnerability may lead to high confidentiality impact due to potential data exposure, which could violate GDPR and HIPAA requirements for protecting sensitive data. Compliance risks arise from unauthorized access to confidential information.

Mitigation Strategies

Apply the latest firmware or microcode updates provided by Intel for Intel Xeon 6 Scalable processors with Intel TDX. Ensure your system is running the most recent patches and monitor Intel's security advisories for further updates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-31938. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart