Lucene search

K
cveIntelCVE-2019-11090
HistoryDec 18, 2019 - 10:15 p.m.

CVE-2019-11090

2019-12-1822:15:12
CWE-362
intel
web.nvd.nist.gov
73
cve-2019-11090
intel ptt
intel txe
intel sps
information disclosure
cryptographic timing
network security

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

53.8%

Cryptographic timing conditions in the subsystem for Intel® PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel® TXE 3.1.70 and 4.0.20; Intel® SPS before versions SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, SPS_E3_04.01.04.086.0, SPS_E3_04.08.04.047.0 may allow an unauthenticated user to potentially enable information disclosure via network access.

Affected configurations

Nvd
Node
intelplatform_trust_technology_firmwareRange11.011.8.70
OR
intelplatform_trust_technology_firmwareRange11.1011.11.70
OR
intelplatform_trust_technology_firmwareRange11.2011.22.70
OR
intelplatform_trust_technology_firmwareRange12.012.0.45
OR
intelplatform_trust_technology_firmwareRange13.013.0.0
OR
intelplatform_trust_technology_firmwareRange14.0.014.0.10
OR
intelserver_platform_services_firmware
OR
intelserver_platform_services_firmwareRangesps_e3_04.01.00.000.0sps_e3_04.01.04.086.0
OR
intelserver_platform_services_firmwareRangesps_e5_04.00.00.000.0sps_e5_04.01.04.305.0
OR
intelserver_platform_services_firmwareRangesps_soc-a_04.00.00.000.0sps_soc-a_04.00.04.191.0
OR
intelserver_platform_services_firmwareRangesps_soc-x_04.00.00.000.0sps_soc-x_04.00.04.108.0
OR
inteltrusted_execution_engine_firmwareRange3.03.1.70
OR
inteltrusted_execution_engine_firmwareRange4.04.0.20
VendorProductVersionCPE
intelplatform_trust_technology_firmware*cpe:2.3:o:intel:platform_trust_technology_firmware:*:*:*:*:*:*:*:*
intelserver_platform_services_firmware*cpe:2.3:o:intel:server_platform_services_firmware:*:*:*:*:*:*:*:*
inteltrusted_execution_engine_firmware*cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Intel(R) PTT",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "See provided reference"
      }
    ]
  }
]

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

5.7

Confidence

High

EPSS

0.002

Percentile

53.8%