Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-11139

21
FAUCET Score

CVE-2019-11139 describes an improper conditions check in the voltage modulation interface of certain Intel Xeon Scalable Processors, potentially leading to a denial of service. This vulnerability, affecting products like Debian and openSUSE, has a CVSS score of 6.0 (Medium) due to its local access requirement and high impact on availability. While there is no known active exploitation or publicly available exploit code, the vulnerability has garnered minimal community discussion, with one Reddit post mentioning "Zombieload 2.0" in relation to Cascade Lake processors.

Impacted Technologies

VendorProductVersion(s)CPE
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
15.0CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*
15.1CPE matchmatch criteria
cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:intel:xeon_8153_firmware:-:*:*:*:*:*:*:*
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:o:intel:xeon_8156_firmware:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.0MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
1.5
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.36%
Probability of exploitation in next 30 days
EPSS Percentile
28.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0036 is in the 77th percentile among its peer group of 3,720 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (4)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: microcode_ctl-4:20190618-1.20191112.1.el8_1
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: microcode_ctl
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: microcode_ctl
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: microcode_ctl

Vendor Advisories (1)

redhatCVE-2019-11139Moderate

hw: voltage modulation technical advisory

Nov 12, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-11/msg00045.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-11/msg00046.html
Mailing ListThird Party Advisory
lists.debian.org / debian-lts-announce/2019/12/msg00035.html
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Dec/28
Mailing ListThird Party Advisory
support.f5.com / csp/article/K42433061
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
intel.com / content/www/us/en/security-center/advisory/intel-sa-00271.html
Vendor Advisory