2024-07-14 02:06:08 +00:00

371 lines
13 KiB
JSON

{
"id": "CVE-2019-11128",
"sourceIdentifier": "secure@intel.com",
"published": "2019-06-13T16:29:01.543",
"lastModified": "2019-06-24T16:15:14.727",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Insufficient input validation in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access."
},
{
"lang": "es",
"value": "Validaci\u00f3n de entrada insuficiente en sistema firmware para Inte(R) NUC Kit puede permitir a un usuario privilegiado habilitar el aumento de denegaci\u00f3n de servicio y/o revelaci\u00f3n de informaci\u00f3n a trav\u00e9s del acceso local."
}
],
"metrics": {
"cvssMetricV30": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "HIGH",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH",
"baseScore": 6.7,
"baseSeverity": "MEDIUM"
},
"exploitabilityScore": 0.8,
"impactScore": 5.9
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"accessVector": "LOCAL",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 4.6
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 3.9,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"configurations": [
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intel:nuc_kit_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "71AA56A6-EB26-4A62-83EC-6961BC24D4DA"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:-:*:*:*:*:*:*:*",
"matchCriteriaId": "88D13413-C312-450A-90D5-48BEB1A9036E"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_d34010wyx:*:*:*:*:*:*:*",
"matchCriteriaId": "F4C02113-34E3-4C07-93D3-4AA22E9217DF"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_d54250wyx:*:*:*:*:*:*:*",
"matchCriteriaId": "C0E48A01-63CF-4C0F-836B-2BB06A28094F"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_de3815tyb:*:*:*:*:*:*:*",
"matchCriteriaId": "1ED26383-FE24-4730-9593-1B87B51AA651"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_dn2820fykh:*:*:*:*:*:*:*",
"matchCriteriaId": "633D585D-B1A7-4DEF-AC47-F513088F94FE"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc5cpyh:*:*:*:*:*:*:*",
"matchCriteriaId": "77D3091A-D8C4-40AD-958C-C1CDB7C250EC"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc5i3myx:*:*:*:*:*:*:*",
"matchCriteriaId": "97C44293-9E69-4E3E-A59B-27138066B105"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc5i3ryx:*:*:*:*:*:*:*",
"matchCriteriaId": "6B548392-6051-44CA-B8A8-DB3886CE7FBF"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc5i5myx:*:*:*:*:*:*:*",
"matchCriteriaId": "511FE5B3-5AE5-4428-BA4A-5B45941D9B62"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc5i5ryx:*:*:*:*:*:*:*",
"matchCriteriaId": "EC61C3BA-8456-4851-A1F0-E1D6A47F938E"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc5i7ryx:*:*:*:*:*:*:*",
"matchCriteriaId": "E96F930E-F0E1-4611-B205-E0169ECD9491"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc5pgyh:*:*:*:*:*:*:*",
"matchCriteriaId": "D2B59679-B316-46FC-9426-72A8D95B0DE7"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc5ppyh:*:*:*:*:*:*:*",
"matchCriteriaId": "C8728A26-E1A4-4215-8FFE-3638782DA739"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc6cayx:*:*:*:*:*:*:*",
"matchCriteriaId": "6637B704-3905-4F6A-A2CF-DB18E2A776C3"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc6i3syx:*:*:*:*:*:*:*",
"matchCriteriaId": "BE1C6ED2-180E-4C53-8B3A-A9A67FEE2FDA"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc6i5syx:*:*:*:*:*:*:*",
"matchCriteriaId": "548B342B-0E6C-4E74-BF67-450D0E84BA9F"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc6i7kyk:*:*:*:*:*:*:*",
"matchCriteriaId": "4BBFF3B1-237E-4E0D-8B94-E9F2215851E7"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc7cjy:*:*:*:*:*:*:*",
"matchCriteriaId": "AD5262A4-2C3B-4801-870B-3F4D431DEC46"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc7i3bnx:*:*:*:*:*:*:*",
"matchCriteriaId": "36F5E5C2-F307-45CF-ABAF-89164FF2746B"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc7i3dnx:*:*:*:*:*:*:*",
"matchCriteriaId": "BF1903DA-B3FF-4B9B-941D-6F9AD0EBF2A0"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc7i5bnx:*:*:*:*:*:*:*",
"matchCriteriaId": "57B2AFD1-357D-473A-A5A1-ED8F20FBE3A0"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc7i5dnx:*:*:*:*:*:*:*",
"matchCriteriaId": "A5CDAC90-836E-45B3-BFA3-32268E54064A"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc7i7bnx:*:*:*:*:*:*:*",
"matchCriteriaId": "6B8FE994-6637-4109-A050-C98A0A1BEFEA"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc7i7dnx:*:*:*:*:*:*:*",
"matchCriteriaId": "09834DD2-6FD4-4A70-AAAF-EF1814DF0732"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc7pjy:*:*:*:*:*:*:*",
"matchCriteriaId": "93745511-0B33-4F55-9021-318B751087A7"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc8i3cyx:*:*:*:*:*:*:*",
"matchCriteriaId": "72DFFFA1-B4CD-44FA-9FDB-1DCC39E06491"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc8i5bex:*:*:*:*:*:*:*",
"matchCriteriaId": "A23E8A97-3460-4C6F-BA5C-0188DF367AB0"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc8i7bex:*:*:*:*:*:*:*",
"matchCriteriaId": "1D44CAA8-EAA5-4997-8C43-169D96776D0F"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc8i7hnk:*:*:*:*:*:*:*",
"matchCriteriaId": "D86F9BA9-430F-4081-925F-0F59E1ADF1D3"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:nuc_kit_nuc8i3bex:nuc_kit_nuc8i7hvk:*:*:*:*:*:*:*",
"matchCriteriaId": "88A2B949-34AB-4C5D-84C0-CC502A887208"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intel:compute_card_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "0F811493-1AB4-47BC-B942-2E93A7349843"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_card_cd1c64gk:-:*:*:*:*:*:*:*",
"matchCriteriaId": "F05A36D1-E417-4904-9DBB-C5828F6521B6"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_card_cd1iv128mk:-:*:*:*:*:*:*:*",
"matchCriteriaId": "CFEA643F-FE21-45B0-AC74-D87D7D864D10"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_card_cd1m3128mk:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B1FA6131-F3C8-4B98-B4E8-C320C262F750"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_card_cd1p64gk:-:*:*:*:*:*:*:*",
"matchCriteriaId": "5E3D93D1-5772-4806-9428-9AB26B32D210"
}
]
}
]
},
{
"operator": "AND",
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:o:intel:compute_stick_firmware:-:*:*:*:*:*:*:*",
"matchCriteriaId": "202B4308-A49D-487D-A04D-FE34235F61C5"
}
]
},
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_stick_stck1a32wfc:-:*:*:*:*:*:*:*",
"matchCriteriaId": "E453448C-AA11-48E3-8423-60E62A10D0CA"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_stick_stck1a8lfc:-:*:*:*:*:*:*:*",
"matchCriteriaId": "17AA0B4A-67AF-466E-BCA6-A8654CA99406"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_stick_stk2m364cc:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B4E8B2EE-302C-4019-A20E-025AAB7E8C9E"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_stick_stk2m3w64cc:-:*:*:*:*:*:*:*",
"matchCriteriaId": "B9A90BE5-6136-43A9-BC91-9474D3D0EEF6"
},
{
"vulnerable": false,
"criteria": "cpe:2.3:h:intel:compute_stick_stk2mv64cc:-:*:*:*:*:*:*:*",
"matchCriteriaId": "6B0C9D80-37A3-43E5-B818-55532F613436"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/bid/108766",
"source": "secure@intel.com",
"tags": [
"Third Party Advisory",
"VDB Entry"
]
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/in",
"source": "secure@intel.com",
"tags": [
"Vendor Advisory"
]
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00264.html",
"source": "secure@intel.com"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00264.html?wapkw=2019-11129",
"source": "nvd@nist.gov",
"tags": [
"Patch",
"Vendor Advisory"
]
}
]
}