Xeon D 2191
Vendor:
First CVE: May 17, 2019 · Active for 7 years
18
Total CVEs
More Total CVEs than 93% of tracked products
6.0
Avg CVEs / Year
Higher CVE frequency than 90% of tracked products
6.4
Avg CVSS
Higher Avg CVSS than 27% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xeon D 2191 over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 17, 2019
7 years ago
Most Recent CVE
Aug 18, 2022
1,439 days ago
CVE Severity & Scoring
Xeon D 219118 CVEs
89%
11%
All CVEs352,719 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local16 (88.9%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical2 (11.1%)
Adjacent Network0 (0.0%)
Attack Complexity
Low17 (94.4%)
High1 (5.6%)
Unknown0 (0.0%)
User Interaction
None18 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low5 (27.8%)
High11 (61.1%)
None2 (11.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (18 CVEs).
18 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-0144MEDIUM Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access. | Jul 14, 2021 | 6.7 | 24 | NO | NO |
CVE-2021-0114MEDIUM Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | Aug 16, 2021 | 6.7 | 23 | NO | NO |
CVE-2020-8700MEDIUM Improper input validation in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | Jun 9, 2021 | 6.7 | 23 | NO | NO |
CVE-2018-12207MEDIUM Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of se | Nov 14, 2019 | 6.5 | 23 | NO | NO |
CVE-2020-8670MEDIUM Race condition in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | Jun 9, 2021 | 6.4 | 22 | NO | NO |
CVE-2019-11137HIGH Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) | Nov 14, 2019 | 8.2 | 22 | NO | NO |
CVE-2019-0126MEDIUM Insufficient access control in silicon reference firmware for Intel(R) Xeon(R) Scalable Processor, Intel(R) Xeon(R) Processor D Family may allow a privileged user to potentially en | May 17, 2019 | 6.7 | 22 | NO | NO |
CVE-2022-26373MEDIUM Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local | Aug 18, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-21233MEDIUM Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | Aug 18, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-0004MEDIUM Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user | May 12, 2022 | 6.8 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (18 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (18 CVEs).
Media Mentions
Signals from CVEs in this product scope (18 CVEs).
Top CNAs Publishing CVEs For Xeon D 2191
Top CWEs
Versions
No cataloged versions.