CVE-2019-11157 is a medium-severity vulnerability affecting certain Intel processors, stemming from improper voltage setting checks. This flaw allows a privileged local user to potentially achieve escalation of privilege or information disclosure. With a CVSS score of 6.7, it requires high privileges and local access, but has a high impact on confidentiality, integrity, and availability. While there is no known public exploit code or active exploitation (KEV is "No"), the vulnerability has garnered significant community discussion and media coverage, indicating notable interest in its potential.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e3-1585_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e3-1585l_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e3-1578l_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e3-1575m_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:intel:xeon_e3-1565l_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.