ID

VAR-202508-1000


CVE

CVE-2025-21090


TITLE

Intel Xeon Processors Denial of Service Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2025-21339

DESCRIPTION

Missing reference to active allocated resource for some Intel(R) Xeon(R) processors may allow an authenticated user to potentially enable denial of service via local access. Intel Xeon Processors are a series of processors designed for enterprise servers, workstations, and high-performance computing (HPC) markets. They primarily serve data centers, cloud computing, and artificial intelligence. Attackers can exploit this vulnerability to cause a denial of service

Trust: 1.44

sources: NVD: CVE-2025-21090 // CNVD: CNVD-2025-21339

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-21339

AFFECTED PRODUCTS

vendor:intelmodel:xeon processorsscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2025-21339

CVSS

SEVERITY

CVSSV2

CVSSV3

secure@intel.com: CVE-2025-21090
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2025-21339
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-21339
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:S/C:N/I:N/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: SINGLE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: COMPLETE
exploitabilityScore: 3.1
impactScore: 6.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

secure@intel.com: CVE-2025-21090
baseSeverity: MEDIUM
baseScore: 6.5
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: CHANGED
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: HIGH
exploitabilityScore: 2.0
impactScore: 4.0
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-21339 // NVD: CVE-2025-21090

PROBLEMTYPE DATA

problemtype:CWE-771

Trust: 1.0

sources: NVD: CVE-2025-21090

PATCH

title:Patch for Intel Xeon Processors Denial of Service Vulnerabilityurl:https://www.cnvd.org.cn/patchInfo/show/732286

Trust: 0.6

sources: CNVD: CNVD-2025-21339

EXTERNAL IDS

db:NVDid:CVE-2025-21090

Trust: 1.6

db:CNVDid:CNVD-2025-21339

Trust: 0.6

sources: CNVD: CNVD-2025-21339 // NVD: CVE-2025-21090

REFERENCES

url:https://intel.com/content/www/us/en/security-center/advisory/intel-sa-01313.html

Trust: 1.0

url:https://nvd.nist.gov/vuln/detail/cve-2025-21090

Trust: 0.6

sources: CNVD: CNVD-2025-21339 // NVD: CVE-2025-21090

SOURCES

db:CNVDid:CNVD-2025-21339
db:NVDid:CVE-2025-21090

LAST UPDATE DATE

2025-09-18T23:10:35.469000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-21339date:2025-09-16T00:00:00
db:NVDid:CVE-2025-21090date:2025-08-13T17:34:12.350

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-21339date:2025-09-15T00:00:00
db:NVDid:CVE-2025-21090date:2025-08-12T17:15:30.857