SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-14615

Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.

MEDIUM 5.5EPSS 1.45%

Does this matter?

Lower severity and a low EPSS score (1.45%). Track it; it rarely justifies an emergency change on its own.

Description

Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
1.45% probability · 72th percentile
CISA KEV
Not listed
Affected
canonical/ubuntu linux · intel/atom e3805 · intel/atom e3815 · intel/atom e3825 · intel/atom e3826 · intel/atom e3827 · intel/atom e3845 · intel/atom e620 · intel/atom e620t · intel/atom e640 · intel/atom e640t · intel/atom e660 · intel/atom e660t · intel/atom e680 · intel/atom e680t · intel/atom x3-c3130 · intel/atom x3-c3200rk · intel/atom x3-c3230rk · intel/atom x3-c3405 · intel/atom x3-c3445 · +40 more
Source
secure@intel.com

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.