First published: Wed Dec 18 2019(Updated: )
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Active Management Technology Firmware | >=11.0<11.8.70 | |
Intel Active Management Technology Firmware | >=11.10<11.11.70 | |
Intel Active Management Technology Firmware | >=11.20<11.22.70 | |
Intel Active Management Technology Firmware | >=12.0<12.0.45 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-11100 is medium.
Intel Active Management Technology Firmware versions 11.0 to 11.8.70, 11.10 to 11.11.70, 11.20 to 11.22.70, and 12.0 to 12.0.45 are affected by CVE-2019-11100.
The vulnerability in CVE-2019-11100 is insufficient input validation in the subsystem for Intel AMT.
An unauthenticated user with physical access may be able to enable information disclosure.
Yes, Intel has released a security advisory with mitigation steps for CVE-2019-11100. Please refer to their advisory for more information.