CVE-2019-11135

MEDIUMCVSS 6.5/10EPSS 3.13%

Last modified

CVE-2019-11135 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.. EPSS estimates a 3.13% chance of exploitation in the next 30 days.

Description

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

EPSS Probability
3.13%

86.2th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
OpensuseLeap15.0
OpensuseLeap15.1
FedoraprojectFedora30
FedoraprojectFedora31
SlackwareSlackware14.2
HpApollo 4200 Firmware< 2.20
HpApollo 2000 Firmware< 2.20
HpProliant Bl460c Firmware< 2.20
HpProliant Dl580 Firmware< 2.20
HpProliant Dl560 Firmware< 2.20
HpProliant Dl380 Firmware< 2.20
HpProliant Dl360 Firmware< 2.20
HpProliant Dl180 Firmware< 2.20
HpProliant Dl160 Firmware< 2.20
HpProliant Dl120 Firmware< 2.20
HpProliant Dl20 Firmware< 2.10
HpProliant Ml350 Firmware< 2.20
HpProliant Ml110 Firmware< 2.20
HpProliant Ml30 Firmware< 2.10
HpProliant Xl450 Firmware< 2.20
HpProliant Xl270d Firmware< 2.20
HpProliant Xl230k Firmware< 2.20
HpProliant Xl190r Firmware< 2.20
HpProliant Xl170r Firmware< 2.20
HpSynergy 480 Firmware< 2.20
HpSynergy 660 Firmware< 2.20
HpProliant E910 Firmware< 2.20
IntelCore I7-10510y FirmwareAll versions
IntelCore I5-10310y FirmwareAll versions
IntelCore I5-10210y FirmwareAll versions
IntelCore I5-10110y FirmwareAll versions
IntelCore I7-8500y FirmwareAll versions
IntelCore I5-8310y FirmwareAll versions
IntelCore I5-8210y FirmwareAll versions
IntelCore I5-8200y FirmwareAll versions
IntelCore M3-8100y FirmwareAll versions
IntelXeon 8253 FirmwareAll versions
IntelXeon 8256 FirmwareAll versions
IntelXeon 8260 FirmwareAll versions
IntelXeon 8260l FirmwareAll versions
IntelXeon 8260m FirmwareAll versions
IntelXeon 8260y FirmwareAll versions
IntelXeon 8268 FirmwareAll versions
IntelXeon 8270 FirmwareAll versions
IntelXeon 8276 FirmwareAll versions
IntelXeon 8276l FirmwareAll versions
IntelXeon 8276m FirmwareAll versions
IntelXeon 8280 FirmwareAll versions
IntelXeon 8280l FirmwareAll versions
IntelXeon 8280m FirmwareAll versions

Showing 50 of 180 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-11135?
TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.
How severe is CVE-2019-11135?
CVE-2019-11135 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 3.13% probability of exploitation in the next 30 days.
How do I fix CVE-2019-11135?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-11135?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST