Authentication bypass by capture-replay in RPMB protocol message authentication subsystem in Intel(R) TXE versions before 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
A capture-replay flaw exists when the design of the product makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).
Link | Tags |
---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391 | vendor advisory |
https://security.netapp.com/advisory/ntap-20201113-0005/ | third party advisory |