CVE-2019-0119
Buffer overflow vulnerability in system firmware for Intel(R) Xeon(R) Processor D Family, Intel(R) Xeon(R) Scalable Processor, Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow a privileged user to potentially enable…
Does this matter?
Lower severity and a low EPSS score (0.43%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow vulnerability in system firmware for Intel(R) Xeon(R) Processor D Family, Intel(R) Xeon(R) Scalable Processor, Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.
- CVSS 3.0
- 6.7 MEDIUMCVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.43% probability · 37th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- intel/xeon d-1649n firmware · intel/xeon d-1633n firmware · intel/xeon d-1637 firmware · intel/xeon d-1627 firmware · intel/xeon d-1623n firmware · intel/xeon d-1622 firmware · intel/xeon d-1653n firmware · intel/xeon d-1602 firmware · intel/xeon d-2141i firmware · intel/xeon d-2177nt firmware · intel/xeon d-2161i firmware · intel/xeon d-2143it firmware · intel/xeon d-2146nt firmware · intel/xeon d-2145nt firmware · intel/xeon d-2123it firmware · intel/xeon d-2173it firmware · intel/xeon d-2191 firmware · intel/xeon d-2187nt firmware · intel/xeon d-2142it firmware · intel/xeon d-2163it firmware · +40 more
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/108485
- https://support.f5.com/csp/article/K85585101
- https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00223.htmlVendor Advisory
- http://www.securityfocus.com/bid/108485
- https://support.f5.com/csp/article/K85585101
- https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00223.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.