MEDIUM · 5.3

CVE-2026-20705

Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privilege...

Vulnerability Description

Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

CVSS Score

5.3

MEDIUM

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelTdx Module<= 1.5.28
IntelXeon Bronze 3408U-
IntelXeon Gold 5411N-
IntelXeon Gold 5412U-
IntelXeon Gold 5415-
IntelXeon Gold 5416S-
IntelXeon Gold 5418N-
IntelXeon Gold 5418Y-
IntelXeon Gold 5420-
IntelXeon Gold 6414U-
IntelXeon Gold 6416H-
IntelXeon Gold 6418H-
IntelXeon Gold 6421N-
IntelXeon Gold 6426Y-
IntelXeon Gold 6428N-
IntelXeon Gold 6430-
IntelXeon Gold 6434-
IntelXeon Gold 6434H-
IntelXeon Gold 6438M-
IntelXeon Gold 6438N-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-20705?

CVE-2026-20705 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privilege...

How severe is CVE-2026-20705?

CVE-2026-20705 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2026-20705?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Tdx Module, Intel Xeon Bronze 3408U, Intel Xeon Gold 5411N, Intel Xeon Gold 5412U, Intel Xeon Gold 5415.