Xeon D 2191 Firmware
Vendor:
First CVE: May 17, 2019 · Active for 7 years
8
Total CVEs
More Total CVEs than 87% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 85% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 36% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Xeon D 2191 Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
May 17, 2019
7 years ago
Most Recent CVE
Aug 18, 2022
1,440 days ago
CVE Severity & Scoring
Xeon D 2191 Firmware8 CVEs
88%
13%
All CVEs353,173 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local7 (87.5%)
Network0 (0.0%)
Unknown0 (0.0%)
Physical1 (12.5%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High4 (50.0%)
None1 (12.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-12207MEDIUM Improper invalidation for page table updates by a virtual guest operating system for multiple Intel(R) Processors may allow an authenticated user to potentially enable denial of se | Nov 14, 2019 | 6.5 | 23 | NO | NO |
CVE-2019-11137HIGH Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) | Nov 14, 2019 | 8.2 | 22 | NO | NO |
CVE-2019-0126MEDIUM Insufficient access control in silicon reference firmware for Intel(R) Xeon(R) Scalable Processor, Intel(R) Xeon(R) Processor D Family may allow a privileged user to potentially en | May 17, 2019 | 6.7 | 22 | NO | NO |
CVE-2022-26373MEDIUM Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local | Aug 18, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-21233MEDIUM Improper isolation of shared resources in some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access. | Aug 18, 2022 | 5.5 | 21 | NO | NO |
CVE-2022-0004MEDIUM Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user | May 12, 2022 | 6.8 | 21 | NO | NO |
CVE-2019-0119MEDIUM Buffer overflow vulnerability in system firmware for Intel(R) Xeon(R) Processor D Family, Intel(R) Xeon(R) Scalable Processor, Intel(R) Server Board, Intel(R) Server System and Int | May 17, 2019 | 6.7 | 21 | NO | NO |
CVE-2019-11136MEDIUM Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Famil | Nov 14, 2019 | 6.7 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Xeon D 2191 Firmware
Top CWEs
Versions
No cataloged versions.