First published: Wed Dec 18 2019(Updated: )
Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, SPS_E3_04.01.04.086.0, SPS_E3_04.08.04.047.0 may allow an unauthenticated user to potentially enable information disclosure via network access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Platform Trust Technology Firmware | >=11.0<=11.8.70 | |
Intel Platform Trust Technology Firmware | >=11.10<11.11.70 | |
Intel Platform Trust Technology Firmware | >=11.20<11.22.70 | |
Intel Platform Trust Technology Firmware | >=12.0<12.0.45 | |
Intel Platform Trust Technology Firmware | >=13.0<13.0.0 | |
Intel Platform Trust Technology Firmware | >=14.0.0<14.0.10 | |
Intel Server Platform Services Firmware | ||
Intel Server Platform Services Firmware | >=sps_e3_04.01.00.000.0<sps_e3_04.01.04.086.0 | |
Intel Server Platform Services Firmware | >=sps_e5_04.00.00.000.0<sps_e5_04.01.04.305.0 | |
Intel Server Platform Services Firmware | >=sps_soc-a_04.00.00.000.0<sps_soc-a_04.00.04.191.0 | |
Intel Server Platform Services Firmware | >=sps_soc-x_04.00.00.000.0<sps_soc-x_04.00.04.108.0 | |
Intel Trusted Execution Engine Firmware | >=3.0<3.1.70 | |
Intel Trusted Execution Engine Firmware | >=4.0<4.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11090 is a vulnerability related to cryptographic timing conditions in the Intel Platform Trust Technology Firmware and Intel Server Platform Services Firmware.
The severity of CVE-2019-11090 is medium with a CVSS score of 5.9.
CVE-2019-11090 affects Intel Platform Trust Technology Firmware versions before 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, and 14.0.10.
CVE-2019-11090 affects Intel Server Platform Services Firmware versions before SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, and SPS_E3_04.01.04.086.0.
More information about CVE-2019-11090 can be found at the following link: [Intel Security Advisory INTEL-SA-00241](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html).