Qortora · Search · Indexed page
INTEL-SA-01315 Skip To Main Content Toggle Navigation Sign In My Intel My Tools ? Sign Out English Select Your Language Bahasa Indonesia Deutsch English Español Français Português Tiếng Việt ไทย 한국어 日本語 简体中文 繁體中文 Toggle Search Search Close Search Panel Advanced Search close Sign In to access restricted content Using Intel.com Search You can easily search the entire Intel.com site in several ways. Brand Name: Core i9 Document Number: 123456 Code Name: Emerald Rapids Special Operators: “Ice Lake”, Ice AND Lake, Ice OR Lake, Ice* Quick Links You can also try the quick links below to see results for most popular searches. Product Information Support Drivers & Software Recent Searches Sign In to access restricted content Advanced Search All of these terms Any of these terms Exact term only Find results with All Results Product Information Support Drivers & Software Documentation & Resources Partners Communities Corporate Show results from Only search in Title Description Content ID Search Sign in to access restricted content. The browser version you are using is not recommended for this site. Please consider upgrading to the latest version of your browser by clicking one of the following links. Safari Chrome Edge Firefox The latest security information on Intel® products. 2026.1 IPU, Intel® Chipset Firmware Advisory Intel ID: INTEL-SA-01315 Advisory Category: Firmware Impact of vulnerability: Denial of Service, Information Disclosure Severity rating: HIGH Original release: 02/10/2026 Last revised: 02/10/2026 View all Show less Summary: Potential security vulnerabilities in some Intel® Converged Security and Management Engine (Intel® CSME), some Intel® Active Management Technology (Intel® AMT), and some Intel® Standard Manageability may allow denial of service or information disclosure. Intel is releasing firmware updates to mitigate these potential vulnerabilities. Vulnerability Details: CVEID: CVE-2025-32008 Description: Out-of-bounds write in the firmware for the Intel® AMT and Intel® Standard Manageability within Ring 3: User Applications may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (low) impacts. CVSS Base Score 4.0: 8.7 High CVSS Vector 4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L CVSS Base Score 3.1: 8.6 High CVSS Vector 3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H CVEID: CVE-2025-20080 Description: Null pointer dereference in the firmware for some Intel® AMT and Intel® Standard Manageability within Ring 0: Kernel may allow a denial of service. Network adversary with an unauthenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. CVSS Base Score 4.0: 8.2 High CVSS Vector 4.0: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N CVSS Base Score 3.1: 6.8 Medium CVSS Vector 3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H CVEID: CVE-2025-27708 Description: Out-of-bounds read in the firmware for some Intel® Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts. CVSS Base Score 4.0: 5.6 Medium CVSS Vector 4.0: CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Base Score 3.1: 4.1 Medium CVSS Vector 3.1: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N Affected Products: Chipset/SOC Versions Before CVE ID Intel® C420 Chipset Intel® X299 Chipset Intel® C230 Series Chipset 11.13.1 CVE-2025-32008 CVE-2025-20080 8th Gen Intel® Core™ processor Intel® 200 Series Chipset Intel® 100 Series Chipset 11.9.5 CVE-2025-32008 CVE-2025-20080 8th Gen Intel® Core™ processor 9th Gen Intel® Core™ processor Intel® 300 Series Chipset Intel® C240 Series Chipset Pentium® Gold processor series (G54XXU) Celeron® processor 4000 series 12.1.1 CVE-2025-32008 CVE-2025-20080 Intel® 400 Series Chipset 14.1.79 CVE-2025-32008 CVE-2025-20080 CVE-2025-27708 Intel® 500 Series Chipset Intel® C250 Series Chipset 15.0.55 CVE-2025-32008 CVE-2025-20080 CVE-2025-27708 Intel® C740 Series Chipset 15.20.25 CVE-2025-32008 CVE-2025-20080 CVE-2025-27708 Intel® 600 Series Chipset Intel® 700 series chipset 16.1.40 CVE-2025-32008 CVE-2025-20080 CVE-2025-27708 5th Gen Intel® Xeon® Processor 16.11.25 CVE-2025-32008 CVE-2025-20080 CVE-2025-27708 Intel® Core™ Ultra Processors (Series 1) 18.0.18 CVE-2025-32008 CVE-2025-20080 CVE-2025-27708 Intel® Core™ Ultra Processors (Series 2) 19.0.5 CVE-2025-32008 CVE-2025-20080 CVE-2025-27708 Intel® Core™ Ultra Processors (Series 2) 20.0.5 CVE-2025-32008 CVE-2025-20080 CVE-2025-27708 Recommendation: Intel recommends that users of Intel® Converged Security and Manageability Engine (CSME), Intel® Active Management Technology (AMT), or Intel® Standard Manageability update to the latest version provided by the system manufacturer that addresses these issues. Acknowledgements: The following issues were found internally by Intel employees. Intel would like to thank Tamar Azulay, and Idan Levy. Intel, and nearly the entire technology industry, follows a disclosure practice called Coordinated Disclosure, under which a cybersecurity vulnerability is generally publicly disclosed only after mitigations are available. Revision History Revision Date Description 1.0 02/10/2026 Initial Release View all Show less Legal Notices and Disclaimers Intel provides these materials as-is, with no express or implied warranties. All products, dates, and figures specified are preliminary based on current expectations, and are subject to change without notice. Intel products and services described may contain design defects or errors known as errata, which may cause the product to deviate from published specifications. Current characterized errata are available on request. Intel products that have met their End of Servicing Updates may no longer receive functional and security updates. For additional details on support and servicing, please see this help article. Intel technologies’ features and benefits depend on system configuration and may require enabled hardware, software or service activation. Performance varies depending on system configuration. No product or component can be absolutely secure. Check with your system manufacturer or retailer or learn more at http://intel.com. Some results have been estimated or simulated using internal Intel analysis or architecture simulation or modeling, and provided to you for informational purposes. Any differences in your system hardware, software or configuration may affect your actual performance. © Intel Corporation. Intel, the Intel logo, and other Intel marks are trademarks of Intel Corporation or its subsidiaries United States and other countries. Other names and brands may be claimed as the property of others. Report a Vulnerability If you have information about a security issue or vulnerability affecting an Intel branded product or technology, submit your report via the Intigriti platform, where you'll find eligibility criteria and submission instructions. All vulnerability reports must be submitted through Intigriti. For issues not related to reporting security vulnerabilities, contact Intel PSIRT. For issues related to Intel's external web presence (Intel.com and related subdomains), please contact Intel's External Security Research team. Need product support? If you... Have questions about the security features of an Intel product Require technical support Want product updates or patches Please visit Support & Downloads. Report a Vulnerability Product Support Get Help Company Overview Contact Intel Newsroom Investors Careers Corporate Responsibility Inclusion Public Policy © Intel Corporation Terms of Use *Trademarks Cookies Privacy Supply Chain Transparency Site Map Recycling Your Privacy Choices Notice at Collection Intel technologies may require enabled hardware, software or service activation. // No product or component can be absolutely secure. // Your costs and results may vary. // Performance varies by use, configuration, and other factors. Learn more at intel.com/performanceindex. // See our complete legal Notices and Disclaimers. // Intel is committed to respecting human rights and avoiding causing or contributing to adverse impacts on human rights. See Intel’s Global Human Rights Principles. Intel’s products and software are intended only to be used in applications that do not cause or contribute to adverse impacts on human rights.