MEDIUM · 6.5

CVE-2019-11135

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

Vulnerability Description

TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
OpensuseLeap15.0
FedoraprojectFedora30
SlackwareSlackware14.2
HpApollo 4200 Firmware< 2.20
HpApollo 4200gen10
HpApollo 2000 Firmware< 2.20
HpApollo 2000-
HpProliant Bl460C Firmware< 2.20
HpProliant Bl460Cgen10
HpProliant Dl580 Firmware< 2.20
HpProliant Dl580gen10
HpProliant Dl560 Firmware< 2.20
HpProliant Dl560gen10
HpProliant Dl380 Firmware< 2.20
HpProliant Dl380gen10
HpProliant Dl360 Firmware< 2.20
HpProliant Dl360gen10
HpProliant Dl180 Firmware< 2.20
HpProliant Dl180gen10
HpProliant Dl160 Firmware< 2.20

References

FAQ

What is CVE-2019-11135?

CVE-2019-11135 is a vulnerability with a CVSS score of 6.5 (MEDIUM). TSX Asynchronous Abort condition on some CPUs utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access.

How severe is CVE-2019-11135?

CVE-2019-11135 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-11135?

Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Leap, Fedoraproject Fedora, Slackware Slackware, Hp Apollo 4200 Firmware, Hp Apollo 4200.