CVE-2019-11090: Race Condition
Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPSE504.01.04.305.0, SPSSoC-X04.00.04.108.0, SPSSoC-A04.00.04.191.0, SPSE304.01.04.086.0, SPSE304.08.04.047.0 may allow an unauthenticated user to potentially enable information disclosure via network access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11090?
CVE-2019-11090 is a vulnerability related to cryptographic timing conditions in the Intel Platform Trust Technology Firmware and Intel Server Platform Services Firmware.
What is the severity of CVE-2019-11090?
The severity of CVE-2019-11090 is medium with a CVSS score of 5.9.
How does CVE-2019-11090 affect Intel Platform Trust Technology Firmware?
CVE-2019-11090 affects Intel Platform Trust Technology Firmware versions before 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, and 14.0.10.
How does CVE-2019-11090 affect Intel Server Platform Services Firmware?
CVE-2019-11090 affects Intel Server Platform Services Firmware versions before SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, and SPS_E3_04.01.04.086.0.
Where can I find more information about CVE-2019-11090?
More information about CVE-2019-11090 can be found at the following link: [Intel Security Advisory INTEL-SA-00241](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html).