CVE-2025-27707
Description
Exposure of sensitive information to an unauthorized actor for some Edge Orchestrator software before version 24.11.1 for Intel(R) Tiber(TM) Edge Platform may allow an authenticated user to potentially enable denial of service via adjacent access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A low-severity info leak in Intel Edge Orchestrator <24.11.1 lets an authenticated user trigger DoS via adjacent access.
Vulnerability
Overview
The vulnerability resides in Edge Orchestrator software for the Intel(R) Tiber(TM) Edge Platform, affecting versions before 24.11.1. The root cause is an exposure of sensitive information to an unauthorized actor, which under specific conditions can be leveraged by an authenticated user to cause a denial of service [1].
Exploitation
Conditions
Exploitation requires the attacker to be authenticated and within adjacent network access to the affected system. The attack vector is classified as adjacent, meaning the attacker must be on the same broadcast or collision domain (e.g., same Wi-Fi network or physical subnet) [1]. No privileges beyond standard user authentication are needed, but the attack complexity is considered high (CVSS 2.6) [1].
Impact
A successful exploit enables the authenticated user to trigger a denial of service condition. While the CVSS severity is rated Low due to the high complexity and adjacent access requirement, the confidentiality impact from the initial information exposure is also considered partial [1].
Mitigation
Intel has released Edge Orchestrator version 24.11.1 to address this vulnerability. Users are advised to update to the latest version as recommended in the Intel Security Advisory INTEL-SA-01317 [1]. No workarounds or interim fixes have been published.
AI Insight generated on May 19, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <24.11.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.