CVE-2019-11137High· 8.2▾ TwilightInsufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) proc…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 45.1 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
xeon_platinum_8253_firmwarexeon_platinum_8256_firmwarexeon_platinum_8260_firmwarexeon_platinum_8276_firmwarexeon_platinum_8276m_firmwarexeon_platinum_8276l_firmwarexeon_platinum_8280l_firmwarexeon_platinum_8260l_firmwarexeon_platinum_8280m_firmwarexeon_platinum_8260m_firmwarexeon_platinum_8280_firmwarexeon_platinum_8260y_firmwarexeon_platinum_8268_firmwarexeon_platinum_8270_firmwarexeon_platinum_8274_firmwarexeon_platinum_8284_firmwarexeon_platinum_9242_firmwarexeon_platinum_9282_firmwarexeon_platinum_8153_firmwarexeon_platinum_8156_firmwarexeon_platinum_8158_firmwarexeon_platinum_8176_firmwarexeon_platinum_8160_firmwarexeon_platinum_8164_firmwarexeon_platinum_8168_firmwarexeon_platinum_8170_firmwarexeon_platinum_8180_firmwarexeon_platinum_8160t_firmwarexeon_platinum_8160f_firmwarexeon_platinum_8176f_firmwarexeon_gold_6210u_firmwarexeon_gold_6244_firmwarexeon_gold_6212u_firmwarexeon_gold_6240_firmwarexeon_gold_5218_firmwarexeon_gold_6230_firmwarexeon_gold_5222_firmwarexeon_gold_6238t_firmwarexeon_gold_6248_firmwarexeon_gold_6252_firmwarexeon_gold_6242_firmwarexeon_gold_6240y_firmwarexeon_gold_5217_firmwarexeon_gold_6238m_firmwarexeon_gold_5218n_firmwarexeon_gold_6226_firmwarexeon_gold_6254_firmwarexeon_gold_5220_firmwarexeon_gold_6238l_firmwarexeon_gold_5218b_firmwarexeon_gold_6240l_firmwarexeon_gold_6238_firmwarexeon_gold_6240m_firmwarexeon_gold_5220s_firmwarexeon_gold_5215_firmwarexeon_gold_6222v_firmwarexeon_gold_6252n_firmwarexeon_gold_5215m_firmwarexeon_gold_6246_firmwarexeon_gold_5215l_firmwarexeon_gold_5218t_firmwarexeon_gold_5220t_firmwarexeon_gold_6209u_firmwarexeon_gold_6262v_firmwarexeon_gold_5122_firmwarexeon_gold_6138_firmwarexeon_gold_6148_firmwarexeon_gold_5120t_firmwarexeon_gold_6136_firmwarexeon_gold_6150_firmwarexeon_gold_6152_firmwarexeon_gold_6130_firmwarexeon_gold_6128_firmwarexeon_gold_5118_firmwarexeon_gold_6134_firmwarexeon_gold_6126_firmwarexeon_gold_5120_firmwarexeon_gold_5115_firmwarexeon_gold_6154_firmwarexeon_gold_6140_firmwarexeon_gold_6140m_firmwarexeon_gold_6132_firmwarexeon_gold_6138t_firmwarexeon_gold_6142f_firmwarexeon_gold_6130t_firmwarexeon_gold_6138f_firmwarexeon_gold_6130f_firmwarexeon_gold_6126t_firmwarexeon_gold_6126f_firmwarexeon_gold_6148f_firmwarexeon_gold_6146_firmwarexeon_gold_6144_firmwarexeon_silver_4209t_firmwarexeon_silver_4210_firmwarexeon_silver_4214_firmwarexeon_silver_4214y_firmwarexeon_silver_4215_firmwarexeon_silver_4208_firmwarexeon_silver_4216_firmwarexeon_silver_4116_firmwareRefer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2019-11136Medium· 6.7Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escal…
CVE-2026-27765Medium· 5.5Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service
CVE-2020-12322Medium· 6.5Improper input validation in some Intel(R) Wireless Bluetooth(R) products before version 21.110 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
CVE-2019-14566High· 7.8Insufficient input validation in Intel(R) SGX SDK multiple Linux and Windows versions may allow an authenticated user to enable information disclosure, escalation of privilege or denial of service via local access.
CVE-2021-0158Medium· 6.7Improper input validation in the BIOS firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
CVE-2023-47855Medium· 6.0Improper input validation in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable escalation of privilege via local access.