CVE-2019-14615
Last modified
CVE-2019-14615 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.. EPSS estimates a 1.45% chance of exploitation in the next 30 days.
Description
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Canonical | Ubuntu Linux | 14.04 |
| Canonical | Ubuntu Linux | 16.04 |
| Canonical | Ubuntu Linux | 18.04 |
| Canonical | Ubuntu Linux | 19.10 |
| Intel | Atom E3805 | All versions |
| Intel | Atom E3815 | All versions |
| Intel | Atom E3825 | All versions |
| Intel | Atom E3826 | All versions |
| Intel | Atom E3827 | All versions |
| Intel | Atom E3845 | All versions |
| Intel | Atom E620 | All versions |
| Intel | Atom E620t | All versions |
| Intel | Atom E640 | All versions |
| Intel | Atom E640t | All versions |
| Intel | Atom E660 | All versions |
| Intel | Atom E660t | All versions |
| Intel | Atom E680 | All versions |
| Intel | Atom E680t | All versions |
| Intel | Atom X3-C3130 | All versions |
| Intel | Atom X3-C3200rk | All versions |
| Intel | Atom X3-C3230rk | All versions |
| Intel | Atom X3-C3405 | All versions |
| Intel | Atom X3-C3445 | All versions |
| Intel | Atom X5-Z8300 | All versions |
| Intel | Atom X5-Z8330 | All versions |
| Intel | Atom X5-Z8500 | All versions |
| Intel | Atom X7-Z8700 | All versions |
| Intel | Atom Z2420 | All versions |
| Intel | Atom Z2460 | All versions |
| Intel | Atom Z2480 | All versions |
| Intel | Atom Z2520 | All versions |
| Intel | Atom Z2560 | All versions |
| Intel | Atom Z2580 | All versions |
| Intel | Atom Z2760 | All versions |
| Intel | Atom Z3460 | All versions |
| Intel | Atom Z3480 | All versions |
| Intel | Atom Z3530 | All versions |
| Intel | Atom Z3560 | All versions |
| Intel | Atom Z3570 | All versions |
| Intel | Atom Z3580 | All versions |
| Intel | Atom Z3590 | All versions |
| Intel | Atom Z3735d | All versions |
| Intel | Atom Z3735e | All versions |
| Intel | Atom Z3735f | All versions |
| Intel | Atom Z3735g | All versions |
| Intel | Atom Z3736f | All versions |
| Intel | Atom Z3736g | All versions |
| Intel | Atom Z3740 | All versions |
| Intel | Atom Z3740d | All versions |
| Intel | Atom Z3745 | All versions |
Showing 50 of 482 affected configurations. See NVD for the full list.
References
- http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.htmlThird Party Advisory, VDB Entry
- https://usn.ubuntu.com/4253-1/Third Party Advisory
- https://usn.ubuntu.com/4253-2/Third Party Advisory
- https://usn.ubuntu.com/4254-1/Third Party Advisory
- https://usn.ubuntu.com/4254-2/Third Party Advisory
- https://usn.ubuntu.com/4255-1/Third Party Advisory
- https://usn.ubuntu.com/4255-2/Third Party Advisory
- http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.htmlThird Party Advisory, VDB Entry
- https://usn.ubuntu.com/4253-1/Third Party Advisory
- https://usn.ubuntu.com/4253-2/Third Party Advisory
- https://usn.ubuntu.com/4254-1/Third Party Advisory
- https://usn.ubuntu.com/4254-2/Third Party Advisory
- https://usn.ubuntu.com/4255-1/Third Party Advisory
- https://usn.ubuntu.com/4255-2/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-14615?
How severe is CVE-2019-14615?
How do I fix CVE-2019-14615?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2019
- CVE-2019-1461A denial of service vulnerability exists in Microsoft Word s…6.5
- CVE-2019-14610Improper access control in firmware for Intel(R) NUC(R) may …7.8
- CVE-2019-14611Integer overflow in firmware for Intel(R) NUC(R) may allow a…6.7
- CVE-2019-14612Out of bounds write in firmware for Intel(R) NUC(R) may allo…6.7
- CVE-2019-14613Improper access control in driver for Intel(R) VTune(TM) Amp…7.8
- CVE-2019-14614Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14616Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14617Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14618Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-14619Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2019-1462A remote code execution vulnerability exists in Microsoft Po…7.8
- CVE-2019-14620Insufficient control flow management for some Intel(R) Wirel…6.5
Are you affected by CVE-2019-14615?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
