CVE Tools

4th Generation Intel Xeon Scalable Processors

18 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for 4th Generation Intel Xeon Scalable Processors, a product in the hardware firmware space. Use it to gauge the current risk picture and drill into individual advisories.

4th Generation Intel Xeon Scalable Processors CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
4th Generation Intel Xeon Scalable Processors CVEs per month
MonthCVEs
2024-100
2024-112
2024-120
2025-010
2025-027
2025-030
2025-040
2025-051
2025-060
2025-070
2025-083
2025-090
2025-100
2025-110
2025-120
2026-010
2026-020
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 18 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • High633%
  • Medium1161%
  • Low16%

Latest CVEs

The 15 most recently published vulnerabilities affecting 4th Generation Intel Xeon Scalable Processors.

  1. CVE-2025-21090Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access.6.5
  2. CVE-2025-20109Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.7.8
  3. CVE-2025-20053Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access.7.2
  4. CVE-2025-20103Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access.6.5
  5. CVE-2024-31068Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access.5.3
  6. CVE-2024-37020Sequence of processor instructions leads to unexpected behavior in the Intel(R) DSA V1.0 for some Intel(R) Xeon(R) Processors may allow an authenticated user to potentially enable denial of service...3.8
  7. CVE-2024-28047Improper input validation in UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.5.3
  8. CVE-2024-31157Improper initialization in UEFI firmware OutOfBandXML module in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.5.3
  9. CVE-2024-39279Insufficient granularity of access control in UEFI firmware in some Intel(R) processors may allow a authenticated user to potentially enable denial of service via local access.6.5
  10. CVE-2024-21859Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.5.3
  11. CVE-2024-31155Improper buffer restrictions in the UEFI firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.7.5
  12. CVE-2024-21853Improper finite state machines (FSMs) in the hardware logic in some 4th and 5th Generation Intel(R) Xeon(R) Processors may allow an authorized user to potentially enable denial of service via local...4.7
  13. CVE-2024-23918Improper conditions check in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via l...8.8
  14. CVE-2024-22374Insufficient control flow management for some Intel(R) Xeon Processors may allow an authenticated user to potentially enable denial of service via local access.6.5
  15. CVE-2023-22655Protection mechanism failure in some 3rd and 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privi...6.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store