CVE-2019-11100: Input Validation
Published Dec 18, 2019
·Updated
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.
Affected Software
4 affected components
Intel Active Management Technology Firmware>=11.0<11.8.70
Intel Active Management Technology Firmware>=11.10<11.11.70
Intel Active Management Technology Firmware>=11.20<11.22.70
Intel Active Management Technology Firmware>=12.0<12.0.45
Event History
Dec 18, 2019
CVE Published
via MITRE·09:09 PM
Data Sourced
via MITRE·09:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-11100?
The severity of CVE-2019-11100 is medium.
2
Which software versions are affected by CVE-2019-11100?
Intel Active Management Technology Firmware versions 11.0 to 11.8.70, 11.10 to 11.11.70, 11.20 to 11.22.70, and 12.0 to 12.0.45 are affected by CVE-2019-11100.
3
What is the vulnerability in CVE-2019-11100?
The vulnerability in CVE-2019-11100 is insufficient input validation in the subsystem for Intel AMT.
4
How can an attacker exploit CVE-2019-11100?
An unauthenticated user with physical access may be able to enable information disclosure.
5
Is there a fix available for CVE-2019-11100?
Yes, Intel has released a security advisory with mitigation steps for CVE-2019-11100. Please refer to their advisory for more information.