CVE Tools

4th Gen Intel Xeon Scalable Processors

18 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for 4th Gen Intel Xeon Scalable Processors, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

4th Gen Intel Xeon Scalable Processors CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
4th Gen Intel Xeon Scalable Processors CVEs per month
MonthCVEs
2024-100
2024-112
2024-120
2025-010
2025-021
2025-030
2025-040
2025-051
2025-060
2025-070
2025-084
2025-090
2025-100
2025-110
2025-120
2026-010
2026-027
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High633%
  • Medium1161%
  • Low16%

Latest CVEs

The 15 most recently published vulnerabilities affecting 4th Gen Intel Xeon Scalable Processors.

  1. CVE-2025-32467Use of uninitialized variable for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a hi...4.1
  2. CVE-2025-32007Out-of-bounds read for some TDX before version tdx module 1.5.24 within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a low compl...4.4
  3. CVE-2025-31944Race condition for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack ...5.3
  4. CVE-2025-31648Improper handling of values in the microcode flow for some Intel(R) Processor Family may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high...3.9
  5. CVE-2025-30513Race condition for some TDX Module within Ring 0: Hypervisor may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable ...7.9
  6. CVE-2025-27940Out-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Software side channel adversary with a privileged user combined with a hi...4.1
  7. CVE-2025-27572Exposure of sensitive information during transient execution for some TDX within Ring 0: Hypervisor may allow an information disclosure. Authorized adversary with a privileged user combined with a ...4.1
  8. CVE-2025-24305Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) processors may allow a privileged user to potentially enable escalation of privil...7.2
  9. CVE-2025-22392Out-of-bounds read in firmware for some Intel(R) AMT and Intel(R) Standard Manageability may allow a privileged user to potentially enable information disclosure via network access.4.4
  10. CVE-2025-20109Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.7.8
  11. CVE-2025-20067Observable timing discrepancy in firmware for some Intel(R) CSME and Intel(R) SPS may allow a privileged user to potentially enable information disclosure via local access.6.0
  12. CVE-2024-45332Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an...5.6
  13. CVE-2024-36293Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.6.5
  14. CVE-2024-24985Exposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalation of privilege via local access.7.2
  15. CVE-2024-22185Time-of-check Time-of-use Race Condition in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalation of privilege via local access.7.2

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store