HIGH · 7.8

CVE-2019-11094

Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure v...

Vulnerability Description

Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelNuc Kit Firmware-
IntelNuc Kit D33217Gke-
IntelNuc Kit D53427Rke-
IntelNuc Kit D54250Wyb-
IntelNuc Kit De3815Tybe-
IntelNuc Kit Dn2820Fykh-
IntelNuc Kit Nuc5Cpyh-
IntelNuc Kit Nuc5I3Myhe-
IntelNuc Kit Nuc5I5Myhe-
IntelNuc Kit Nuc5I7Ryh-
IntelNuc Kit Nuc5Pgyh-
IntelNuc Kit Nuc6Cays-
IntelNuc Kit Nuc6I5Syh-
IntelNuc Kit Nuc6I7Kyk-
IntelNuc Kit Nuc7Cjyh-
IntelNuc Kit Nuc7I3Dnhe-
IntelNuc Kit Nuc7I5Dnke-
IntelNuc Kit Nuc7I7Bnh-
IntelNuc Kit Nuc7I7Dnke-
IntelNuc Kit Nuc8I7Hnk-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-11094?

CVE-2019-11094 is a vulnerability with a CVSS score of 7.8 (HIGH). Insufficient input validation in system firmware for Intel (R) NUC Kit may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure v...

How severe is CVE-2019-11094?

CVE-2019-11094 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-11094?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Nuc Kit Firmware, Intel Nuc Kit D33217Gke, Intel Nuc Kit D53427Rke, Intel Nuc Kit D54250Wyb, Intel Nuc Kit De3815Tybe.