Attacker Value
Unknown
0
CVE-2019-0152
0
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2019-0152
(Last updated November 08, 2023) ▾
MITRE ATT&CK
Log in to add MITRE ATT&CK tag
Add MITRE ATT&CK tactics and techniques that apply to this CVE.
MITRE ATT&CK
Select the MITRE ATT&CK Tactics that apply to this CVE
Collection
Select any Techniques used:
Command and Control
Select any Techniques used:
Credential Access
Select any Techniques used:
Defense Evasion
Select any Techniques used:
Discovery
Select any Techniques used:
Execution
Select any Techniques used:
Exfiltration
Select any Techniques used:
Impact
Select any Techniques used:
Initial Access
Select any Techniques used:
Lateral Movement
Select any Techniques used:
Persistence
Select any Techniques used:
Privilege Escalation
Select any Techniques used:
Topic Tags
Select the tags that apply to this CVE (Assessment added tags are disabled and cannot be removed)
What makes this of high-value to an attacker?
What makes this of low-value to an attacker?
Description
Insufficient memory protection in System Management Mode (SMM) and Intel® TXT for certain Intel® Xeon® Processors may allow a privileged user to potentially enable escalation of privilege via local access.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
Data provided by the National Vulnerability Database (NVD)
Base Score:
6.7 Medium
Impact Score:
5.9
Exploitability Score:
0.8
Attack Vector (AV):
Local
Attack Complexity (AC):
Low
Privileges Required (PR):
High
User Interaction (UI):
None
Scope (S):
Unchanged
Confidentiality (C):
High
Integrity (I):
High
Availability (A):
High
General Information
Offensive Application
Unknown
Utility Class
Unknown
Ports
Unknown
OS
Unknown
Vulnerable Versions
2019.2 IPU – Intel(R) Processor Security See provided reference
Prerequisites
Unknown
Discovered By
Unknown
PoC Author
Unknown
Metasploit Module
Unknown
Reporter
Unknown
Vendors
Products
- xeon bronze 3104 firmware -,
- xeon bronze 3106 firmware -,
- xeon bronze 3204 firmware -,
- xeon d-2123it firmware -,
- xeon d-2141i firmware -,
- xeon d-2142it firmware -,
- xeon d-2143it firmware -,
- xeon d-2145nt firmware -,
- xeon d-2146nt firmware -,
- xeon d-2161i firmware -,
- xeon d-2163it firmware -,
- xeon d-2166nt firmware -,
- xeon d-2173it firmware -,
- xeon d-2177nt firmware -,
- xeon d-2183it firmware -,
- xeon d-2187nt firmware -,
- xeon gold 5115 firmware -,
- xeon gold 5118 firmware -,
- xeon gold 5120 firmware -,
- xeon gold 5120t firmware -,
- xeon gold 5122 firmware -,
- xeon gold 5215 firmware -,
- xeon gold 5215l firmware -,
- xeon gold 5215m firmware -,
- xeon gold 5217 firmware -,
- xeon gold 5218 firmware -,
- xeon gold 5218b firmware -,
- xeon gold 5218n firmware -,
- xeon gold 5218t firmware -,
- xeon gold 5220 firmware -,
- xeon gold 5220s firmware -,
- xeon gold 5220t firmware -,
- xeon gold 5222 firmware -,
- xeon gold 6126 firmware -,
- xeon gold 6126f firmware -,
- xeon gold 6126t firmware -,
- xeon gold 6128 firmware -,
- xeon gold 6130 firmware -,
- xeon gold 6130f firmware -,
- xeon gold 6130t firmware -,
- xeon gold 6132 firmware -,
- xeon gold 6134 firmware -,
- xeon gold 6136 firmware -,
- xeon gold 6138 firmware -,
- xeon gold 6138f firmware -,
- xeon gold 6138t firmware -,
- xeon gold 6140 firmware -,
- xeon gold 6140m firmware -,
- xeon gold 6142f firmware -,
- xeon gold 6144 firmware -,
- xeon gold 6146 firmware -,
- xeon gold 6148 firmware -,
- xeon gold 6148f firmware -,
- xeon gold 6150 firmware -,
- xeon gold 6152 firmware -,
- xeon gold 6154 firmware -,
- xeon gold 6209u firmware -,
- xeon gold 6210u firmware -,
- xeon gold 6212u firmware -,
- xeon gold 6222v firmware -,
- xeon gold 6226 firmware -,
- xeon gold 6230 firmware -,
- xeon gold 6238 firmware -,
- xeon gold 6238l firmware -,
- xeon gold 6238m firmware -,
- xeon gold 6238t firmware -,
- xeon gold 6240 firmware -,
- xeon gold 6240l firmware -,
- xeon gold 6240m firmware -,
- xeon gold 6240y firmware -,
- xeon gold 6242 firmware -,
- xeon gold 6244 firmware -,
- xeon gold 6246 firmware -,
- xeon gold 6248 firmware -,
- xeon gold 6252 firmware -,
- xeon gold 6252n firmware -,
- xeon gold 6254 firmware -,
- xeon gold 6262v firmware -,
- xeon platinum 8153 firmware -,
- xeon platinum 8156 firmware -,
- xeon platinum 8158 firmware -,
- xeon platinum 8160 firmware -,
- xeon platinum 8160f firmware -,
- xeon platinum 8160t firmware -,
- xeon platinum 8164 firmware -,
- xeon platinum 8168 firmware -,
- xeon platinum 8170 firmware -,
- xeon platinum 8176 firmware -,
- xeon platinum 8176f firmware -,
- xeon platinum 8180 firmware -,
- xeon platinum 8253 firmware -,
- xeon platinum 8256 firmware -,
- xeon platinum 8260 firmware -,
- xeon platinum 8260l firmware -,
- xeon platinum 8260m firmware -,
- xeon platinum 8260y firmware -,
- xeon platinum 8268 firmware -,
- xeon platinum 8270 firmware -,
- xeon platinum 8274 firmware -,
- xeon platinum 8276 firmware -,
- xeon platinum 8276l firmware -,
- xeon platinum 8276m firmware -,
- xeon platinum 8280 firmware -,
- xeon platinum 8280l firmware -,
- xeon platinum 8280m firmware -,
- xeon platinum 8284 firmware -,
- xeon platinum 9242 firmware -,
- xeon platinum 9282 firmware -,
- xeon silver 4108 firmware -,
- xeon silver 4109t firmware -,
- xeon silver 4110 firmware -,
- xeon silver 4112 firmware -,
- xeon silver 4114 firmware -,
- xeon silver 4116 firmware -,
- xeon silver 4208 firmware -,
- xeon silver 4209t firmware -,
- xeon silver 4210 firmware -,
- xeon silver 4214 firmware -,
- xeon silver 4214y firmware -,
- xeon silver 4215 firmware -,
- xeon silver 4216 firmware -,
- xeon w-2123 firmware -,
- xeon w-2125 firmware -,
- xeon w-2133 firmware -,
- xeon w-2135 firmware -,
- xeon w-2145 firmware -,
- xeon w-2155 firmware -,
- xeon w-2175 firmware -,
- xeon w-2195 firmware -,
- xeon w-3175x firmware -
References
Additional Info
Authenticated
Unknown
Exploitable
Unknown
Reliability
Unknown
Stability
Unknown
Available Mitigations
Unknown
Shelf Life
Unknown
Userbase/Installbase
Unknown
Patch Effectiveness
Unknown
Rapid7
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: