4.4

CVE-2019-11102

Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.

Data is provided by the National Vulnerability Database (NVD)
IntelDynamic Application Loader SwPlatformconverged_security_management_engine_firmware Version >= 11.0 < 11.8.70
IntelDynamic Application Loader SwPlatformconverged_security_management_engine_firmware Version >= 11.10 < 11.11.70
IntelDynamic Application Loader SwPlatformconverged_security_management_engine_firmware Version >= 11.20 < 11.22.70
IntelDynamic Application Loader SwPlatformconverged_security_management_engine_firmware Version >= 12.0 < 12.0.45
IntelDynamic Application Loader SwPlatformconverged_security_management_engine_firmware Version >= 13.0 < 13.0.10
IntelDynamic Application Loader SwPlatformconverged_security_management_engine_firmware Version >= 14.0.0 < 14.0.10
IntelTrusted Execution Engine Firmware Version >= 3.0 < 3.1.70
IntelTrusted Execution Engine Firmware Version >= 4.0 < 4.0.20
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.355
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.4 0.8 3.6
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvd@nist.gov 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.