{"id":"CVE-2023-47855","title":"Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.","summary":"Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.","severity":"medium","cvss":6,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-20"],"vendor":"intel","product":"tdx_module","affected":["tdx_module < 1.5.05.46.698","hci_compute_node_bios"],"patched":["tdx_module 1.5.05.46.698"],"published":"2024-05-16","updated":"2026-08-31","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2023-47855","references":[{"url":"https://security.netapp.com/advisory/ntap-20240621-0003/","label":"secure@intel.com"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html","label":"secure@intel.com"},{"url":"https://security.netapp.com/advisory/ntap-20240621-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01036.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.00368,"epssPercentile":0.30555,"ingestedAt":"2026-08-31T14:09:16.289Z","slug":"CVE-2023-47855","body":"## Overview\n\nImproper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.\n\n## Affected\n\n- `tdx_module < 1.5.05.46.698`\n- `hci_compute_node_bios`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tdx_module 1.5.05.46.698`","depth":"sunlit","depthScore":33,"depthScoreParts":{"impact":33,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}