Authentication bypass by capture-replay in RPMB protocol message authentication subsystem in Intel(R) TXE versions before 4.0.30 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
https://www.kb.cert.org/vuls/id/231329
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00391