CVE-2026-20709
Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via physical access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.6
- CVSS vector
- CVSS:4.0/AV:P/AC:H/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N
- EPSS probability
- 0.11%
- CWE
- CWE-1394
- Published
- 2026-04-08
- Last modified
- 2026-04-10
Affected products
- n/a Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via physical access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.
Weakness type
Related vulnerabilities
- CVE-2026-75870 — Punk versions before 0.18 for Perl allow session cookie forgery via an empty default HMAC key when a session is declared without a secret
- CVE-2026-54887 — DTLS server cookie bypass during startup window due to empty initial cookie secret
- CVE-2026-5039 — Predictable Default Cryptographic Key Used for DES Encryption in TP-Link TL-WL841N
- CVE-2026-2215 — rachelos WeRSS we-mp-rss JWT auth.py default key
- CVE-2026-25815 — Fortinet FortiOS through 7.6.6 allows attackers to decrypt LDAP credentials stored in device...
- CVE-2025-41742 — Sprecher Automation: SPRECON-E series has a critical vulnerability due to the use of static cryptographic keys in system components
- CVE-2025-41744 — Sprecher Automation: SPRECON-E series has static default key material for TLS connections
- CVE-2025-55049 — Use of Default Cryptographic Key (CWE-1394)