CVE-2019-11102: Input Validation
Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11102?
CVE-2019-11102 is a vulnerability in Intel(R) DAL software for Intel(R) CSME and Intel(R) TXE that may allow a privileged user to potentially enable information disclosure via local access.
What is the severity of CVE-2019-11102?
The severity of CVE-2019-11102 is medium, with a CVSSv3 score of 4.4.
Which software versions are affected by CVE-2019-11102?
CVE-2019-11102 affects Intel(R) DAL software for Intel(R) CSME versions 11.0 to 11.8.70, 11.10 to 11.11.70, 11.20 to 11.22.70, 12.0 to 12.0.45, 13.0 to 13.0.10, 14.0.0 to 14.0.10, and Intel(R) TXE versions 3.0 to 3.1.70, 4.0 to 4.0.20.
How can a privileged user exploit CVE-2019-11102?
A privileged user can potentially enable information disclosure via local access to exploit CVE-2019-11102.
Where can I find more information about CVE-2019-11102?
You can find more information about CVE-2019-11102 in Intel's security advisory at the following link: [Intel Security Advisory](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00241.html).