Vulnerabilities > Intel > Medium

DATE CVE VULNERABILITY TITLE RISK
2019-11-14 CVE-2019-11179 Improper Input Validation vulnerability in Intel Baseboard Management Controller Firmware 2.09
Insufficient input validation in Intel(R) Baseboard Management Controller firmware may allow an authenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-20
6.5
2019-11-14 CVE-2019-11174 Unspecified vulnerability in Intel Baseboard Management Controller Firmware 2.09
Insufficient access control in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel
5.3
2019-11-14 CVE-2019-11172 Out-of-bounds Read vulnerability in Intel Baseboard Management Controller Firmware 2.09
Out of bound read in Intel(R) Baseboard Management Controller firmware may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-125
5.3
2019-11-14 CVE-2019-11136 Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
local
low complexity
intel hpe
6.7
2019-09-16 CVE-2019-11184 Race Condition vulnerability in multiple products
A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.
high complexity
intel netapp CWE-362
4.8
2019-09-16 CVE-2019-11166 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Easy Streaming Wizard
Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authenticated user to potentially enable escalation of privilege via local attack.
local
low complexity
intel CWE-732
6.7
2019-08-19 CVE-2019-11143 Unspecified vulnerability in Intel Authenticate 3.7
Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel
6.7
2019-08-19 CVE-2019-11140 Improper Input Validation vulnerability in Intel products
Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
local
low complexity
intel CWE-20
6.7
2019-07-11 CVE-2018-18095 Improper Authentication vulnerability in Intel SSD DC S4500 Firmware and SSD DC S4600 Firmware
Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user to potentially enable escalation of privilege via physical access.
low complexity
intel CWE-287
6.8
2019-06-13 CVE-2019-11129 Out-of-bounds Write vulnerability in Intel products
Out of bound read/write in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
local
low complexity
intel CWE-787
6.7