CVE-2019-11136Medium· 6.7▾ SunlitInsufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escal…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 36.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
xeon_platinum_8253_firmwarexeon_platinum_8256_firmwarexeon_platinum_8260_firmwarexeon_platinum_8276_firmwarexeon_platinum_8276m_firmwarexeon_platinum_8276l_firmwarexeon_platinum_8280l_firmwarexeon_platinum_8260l_firmwarexeon_platinum_8280m_firmwarexeon_platinum_8260m_firmwarexeon_platinum_8280_firmwarexeon_platinum_8260y_firmwarexeon_platinum_8268_firmwarexeon_platinum_8270_firmwarexeon_platinum_8274_firmwarexeon_platinum_8284_firmwarexeon_platinum_9242_firmwarexeon_platinum_9282_firmwarexeon_platinum_8153_firmwarexeon_platinum_8156_firmwarexeon_platinum_8158_firmwarexeon_platinum_8176_firmwarexeon_platinum_8160_firmwarexeon_platinum_8164_firmwarexeon_platinum_8168_firmwarexeon_platinum_8170_firmwarexeon_platinum_8180_firmwarexeon_platinum_8160t_firmwarexeon_platinum_8160f_firmwarexeon_platinum_8176f_firmwarexeon_gold_6210u_firmwarexeon_gold_6244_firmwarexeon_gold_6212u_firmwarexeon_gold_6240_firmwarexeon_gold_5218_firmwarexeon_gold_6230_firmwarexeon_gold_5222_firmwarexeon_gold_6238t_firmwarexeon_gold_6248_firmwarexeon_gold_6252_firmwarexeon_gold_6242_firmwarexeon_gold_6240y_firmwarexeon_gold_5217_firmwarexeon_gold_6238m_firmwarexeon_gold_5218n_firmwarexeon_gold_6226_firmwarexeon_gold_6254_firmwarexeon_gold_5220_firmwarexeon_gold_6238l_firmwarexeon_gold_5218b_firmwarexeon_gold_6240l_firmwarexeon_gold_6238_firmwarexeon_gold_6240m_firmwarexeon_gold_5220s_firmwarexeon_gold_5215_firmwarexeon_gold_6222v_firmwarexeon_gold_6252n_firmwarexeon_gold_5215m_firmwarexeon_gold_6246_firmwarexeon_gold_5215l_firmwarexeon_gold_5218t_firmwarexeon_gold_5220t_firmwarexeon_gold_6209u_firmwarexeon_gold_6262v_firmwarexeon_gold_5122_firmwarexeon_gold_6138_firmwarexeon_gold_6148_firmwarexeon_gold_5120t_firmwarexeon_gold_6136_firmwarexeon_gold_6150_firmwarexeon_gold_6152_firmwarexeon_gold_6130_firmwarexeon_gold_6128_firmwarexeon_gold_5118_firmwarexeon_gold_6134_firmwarexeon_gold_6126_firmwarexeon_gold_5120_firmwarexeon_gold_5115_firmwarexeon_gold_6154_firmwarexeon_gold_6140_firmwarexeon_gold_6140m_firmwarexeon_gold_6132_firmwarexeon_gold_6138t_firmwarexeon_gold_6142f_firmwarexeon_gold_6130t_firmwarexeon_gold_6138f_firmwarexeon_gold_6130f_firmwarexeon_gold_6126t_firmwarexeon_gold_6126f_firmwarexeon_gold_6148f_firmwarexeon_gold_6146_firmwarexeon_gold_6144_firmwarexeon_silver_4209t_firmwarexeon_silver_4210_firmwarexeon_silver_4214_firmwarexeon_silver_4214y_firmwarexeon_silver_4215_firmwarexeon_silver_4208_firmwarexeon_silver_4216_firmwarexeon_silver_4116_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2019-11137High· 8.2Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) proc…
CVE-2021-0146Medium· 6.8Hardware allows activation of test or debug logic at runtime for some Intel(R) processors which may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
CVE-2021-0114Medium· 6.7Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
CVE-2021-0095Medium· 4.4Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
CVE-2020-12322Medium· 6.5Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
CVE-2020-12321High· 8.8Improper buffer restriction in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.