Improper access control in some 3rd Generation Intel(R) Xeon(R) Scalable processors may allow a privileged user to potentially enable information disclosure via local access.
Conclusion & alert: CVE-2023-23908 is rated Low Risk (24.4/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.01%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.05% | 0.01% | -0.04% |
| 2 | 2025-11-18 | 0.01% | 0.05% | +0.04% |
| 3 | 2025-04-15 | — | 0.01% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.0 | 3.1 | MEDIUM |
|
1.5 | 4.0 | [email protected] |
| 4.4 | 3.1 | MEDIUM |
|
0.8 | 3.6 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
medium | CVE-2023-23908: 1 source package rows (intel-ucode); 7 state rows across 7 repos (3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 7, open 0. | https://security.alpinelinux.org/vuln/CVE-2023-23908 |
debian
|
not yet assigned | CVE-2023-23908 not yet assigned priority: Debian including 1 source packages (intel-microcode), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2023-23908 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2023-23908 |
suse
|
high | CVE-2023-23908 severity important: SUSE including 9 source package names (microcode_ctl-1.17-102.83.81.1, ucode-intel-20230808-1.1, …), 57 product×package rows across 57 product lines (Image SLES12-SP5-SAP-Azure-LI-BYOS-Production, Image SLES12-SP5-SAP-Azure-VLI-BYOS-Production, … (57 product lines)): Fixed 57. | https://www.suse.com/security/cve/CVE-2023-23908/ |
ubuntu
|
medium | CVE-2023-23908 medium priority: Ubuntu including 1 source packages (intel-microcode), 10 status rows across 10 suites (bionic, focal, jammy, lunar, mantic, noble, oracular, trusty, upstream, xenial): released 9, ignored 1. | https://ubuntu.com/security/CVE-2023-23908 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| intel | microcode | < 20230808 | cpe:2.3:o:intel:microcode:*:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| debian | debian_linux | 11.0 | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
| debian | debian_linux | 12.0 | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 37 | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
| fedoraproject | fedora | 38 | cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:* |
| intel | xeon_d-2745nx_firmware | — | cpe:2.3:o:intel:xeon_d-2745nx_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2757nx_firmware | — | cpe:2.3:o:intel:xeon_d-2757nx_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2777nx_firmware | — | cpe:2.3:o:intel:xeon_d-2777nx_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2798nx_firmware | — | cpe:2.3:o:intel:xeon_d-2798nx_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1702_firmware | — | cpe:2.3:o:intel:xeon_d-1702_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1712tr_firmware | — | cpe:2.3:o:intel:xeon_d-1712tr_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1713nt_firmware | — | cpe:2.3:o:intel:xeon_d-1713nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1713nte_firmware | — | cpe:2.3:o:intel:xeon_d-1713nte_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1714_firmware | — | cpe:2.3:o:intel:xeon_d-1714_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1715ter_firmware | — | cpe:2.3:o:intel:xeon_d-1715ter_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1718t_firmware | — | cpe:2.3:o:intel:xeon_d-1718t_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1722ne_firmware | — | cpe:2.3:o:intel:xeon_d-1722ne_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1726_firmware | — | cpe:2.3:o:intel:xeon_d-1726_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1732te_firmware | — | cpe:2.3:o:intel:xeon_d-1732te_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1733nt_firmware | — | cpe:2.3:o:intel:xeon_d-1733nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1734nt_firmware | — | cpe:2.3:o:intel:xeon_d-1734nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1735tr_firmware | — | cpe:2.3:o:intel:xeon_d-1735tr_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1736_firmware | — | cpe:2.3:o:intel:xeon_d-1736_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1736nt_firmware | — | cpe:2.3:o:intel:xeon_d-1736nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1739_firmware | — | cpe:2.3:o:intel:xeon_d-1739_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1746ter_firmware | — | cpe:2.3:o:intel:xeon_d-1746ter_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1747nte_firmware | — | cpe:2.3:o:intel:xeon_d-1747nte_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1748te_firmware | — | cpe:2.3:o:intel:xeon_d-1748te_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1749nt_firmware | — | cpe:2.3:o:intel:xeon_d-1749nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2712t_firmware | — | cpe:2.3:o:intel:xeon_d-2712t_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2733nt_firmware | — | cpe:2.3:o:intel:xeon_d-2733nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2738_firmware | — | cpe:2.3:o:intel:xeon_d-2738_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2752nte_firmware | — | cpe:2.3:o:intel:xeon_d-2752nte_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2752ter_firmware | — | cpe:2.3:o:intel:xeon_d-2752ter_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2753nt_firmware | — | cpe:2.3:o:intel:xeon_d-2753nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2766nt_firmware | — | cpe:2.3:o:intel:xeon_d-2766nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2775te_firmware | — | cpe:2.3:o:intel:xeon_d-2775te_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2776nt_firmware | — | cpe:2.3:o:intel:xeon_d-2776nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2779_firmware | — | cpe:2.3:o:intel:xeon_d-2779_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2786nte_firmware | — | cpe:2.3:o:intel:xeon_d-2786nte_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2795nt_firmware | — | cpe:2.3:o:intel:xeon_d-2795nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2796nt_firmware | — | cpe:2.3:o:intel:xeon_d-2796nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2796te_firmware | — | cpe:2.3:o:intel:xeon_d-2796te_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2798nt_firmware | — | cpe:2.3:o:intel:xeon_d-2798nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2799_firmware | — | cpe:2.3:o:intel:xeon_d-2799_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1602_firmware | — | cpe:2.3:o:intel:xeon_d-1602_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1622_firmware | — | cpe:2.3:o:intel:xeon_d-1622_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1623n_firmware | — | cpe:2.3:o:intel:xeon_d-1623n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1627_firmware | — | cpe:2.3:o:intel:xeon_d-1627_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1633n_firmware | — | cpe:2.3:o:intel:xeon_d-1633n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1637_firmware | — | cpe:2.3:o:intel:xeon_d-1637_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1649n_firmware | — | cpe:2.3:o:intel:xeon_d-1649n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1653n_firmware | — | cpe:2.3:o:intel:xeon_d-1653n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2123it_firmware | — | cpe:2.3:o:intel:xeon_d-2123it_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2141i_firmware | — | cpe:2.3:o:intel:xeon_d-2141i_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2142it_firmware | — | cpe:2.3:o:intel:xeon_d-2142it_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2143it_firmware | — | cpe:2.3:o:intel:xeon_d-2143it_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2145nt_firmware | — | cpe:2.3:o:intel:xeon_d-2145nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2146nt_firmware | — | cpe:2.3:o:intel:xeon_d-2146nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2161i_firmware | — | cpe:2.3:o:intel:xeon_d-2161i_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2163it_firmware | — | cpe:2.3:o:intel:xeon_d-2163it_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2166nt_firmware | — | cpe:2.3:o:intel:xeon_d-2166nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2173it_firmware | — | cpe:2.3:o:intel:xeon_d-2173it_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2177nt_firmware | — | cpe:2.3:o:intel:xeon_d-2177nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2183it_firmware | — | cpe:2.3:o:intel:xeon_d-2183it_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-2187nt_firmware | — | cpe:2.3:o:intel:xeon_d-2187nt_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1513n_firmware | — | cpe:2.3:o:intel:xeon_d-1513n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1523n_firmware | — | cpe:2.3:o:intel:xeon_d-1523n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1533n_firmware | — | cpe:2.3:o:intel:xeon_d-1533n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1543n_firmware | — | cpe:2.3:o:intel:xeon_d-1543n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1553n_firmware | — | cpe:2.3:o:intel:xeon_d-1553n_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1529_firmware | — | cpe:2.3:o:intel:xeon_d-1529_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1539_firmware | — | cpe:2.3:o:intel:xeon_d-1539_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1559_firmware | — | cpe:2.3:o:intel:xeon_d-1559_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1557_firmware | — | cpe:2.3:o:intel:xeon_d-1557_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1567_firmware | — | cpe:2.3:o:intel:xeon_d-1567_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1571_firmware | — | cpe:2.3:o:intel:xeon_d-1571_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1577_firmware | — | cpe:2.3:o:intel:xeon_d-1577_firmware:-:*:*:*:*:*:*:* |
| intel | xeon_d-1518_firmware | — | cpe:2.3:o:intel:xeon_d-1518_firmware:-:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00836.html | Vendor Advisory |
| https://lists.debian.org/debian-lts-announce/2023/08/msg00026.html | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/HKREYYTWUY7ZDNIB2N6H5BUJ3LE5VZPE/ | Mailing List Third Party Advisory |
| https://lists.fedoraproject.org/archives/list/[email protected]/message/OL7WI2TJCWSZIQP2RIOLWHOKLM25M44J/ | Mailing List Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20230824-0003/ | |
| https://www.debian.org/security/2023/dsa-5474 | Third Party Advisory |