CVE-2019-11184

MEDIUMCVSS 4.8/10EPSS 0.75%

Last modified

CVE-2019-11184 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.. EPSS estimates a 0.75% chance of exploitation in the next 30 days.

Description

A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.

Metrics

CVSS 3.1
4.8/10

CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

EPSS Probability
0.75%

50.3th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
Intel6138 FirmwareAll versions
Intel6130t FirmwareAll versions
Intel6130 FirmwareAll versions
Intel6126t FirmwareAll versions
Intel6126 FirmwareAll versions
Intel5120t FirmwareAll versions
Intel5119t FirmwareAll versions
Intel5118 FirmwareAll versions
Intel4116t FirmwareAll versions
Intel4116 FirmwareAll versions
Intel4114t FirmwareAll versions
Intel4110 FirmwareAll versions
Intel4109t FirmwareAll versions
Intel3106 FirmwareAll versions
IntelXeon E5-1428l FirmwareAll versions
IntelXeon E5-2403 FirmwareAll versions
IntelXeon E5-2407 FirmwareAll versions
IntelXeon E5-2418l FirmwareAll versions
IntelXeon E5-2420 FirmwareAll versions
IntelXeon E5-2428l FirmwareAll versions
IntelXeon E5-2430 FirmwareAll versions
IntelXeon E5-2430l FirmwareAll versions
IntelXeon E5-2440 FirmwareAll versions
IntelXeon E5-2448l FirmwareAll versions
IntelXeon E5-2450 FirmwareAll versions
IntelXeon E5-2450l FirmwareAll versions
IntelXeon E5-2470 FirmwareAll versions
IntelXeon E5-4603 FirmwareAll versions
IntelXeon E5-4607 FirmwareAll versions
IntelXeon E5-4610 FirmwareAll versions
IntelXeon E5-4617 FirmwareAll versions
IntelXeon E5-4620 FirmwareAll versions
IntelXeon E5-4640 FirmwareAll versions
IntelXeon E5-4650 FirmwareAll versions
IntelXeon E5-4650l FirmwareAll versions
IntelXeon E5-1620 FirmwareAll versions
IntelXeon E5-1650 FirmwareAll versions
IntelXeon E5-1660 FirmwareAll versions
IntelXeon E5-2603 FirmwareAll versions
IntelXeon E5-2609 FirmwareAll versions
IntelXeon E5-2620 FirmwareAll versions
IntelXeon E5-2630 FirmwareAll versions
IntelXeon E5-2630l FirmwareAll versions
IntelXeon E5-2637 FirmwareAll versions
IntelXeon E5-2640 FirmwareAll versions
IntelXeon E5-2643 FirmwareAll versions
IntelXeon E5-2648l FirmwareAll versions
IntelXeon E5-2650 FirmwareAll versions
IntelXeon E5-2650l FirmwareAll versions
IntelXeon E5-2658 FirmwareAll versions

Showing 50 of 242 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-11184?
A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.
How severe is CVE-2019-11184?
CVE-2019-11184 has a CVSS score of 4.8/10 (MEDIUM severity). The EPSS model estimates a 0.75% probability of exploitation in the next 30 days.
How do I fix CVE-2019-11184?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-11184?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST