Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2019-0119


Buffer overflow vulnerability in system firmware for Intel(R) Xeon(R) Processor D Family, Intel(R) Xeon(R) Scalable Processor, Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.7, requiring local system access to exploit with relatively low complexity without requiring user interaction . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 184 products from intel, from intel, from intel and 181 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2019, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2019-05-17T16:29:01.783

Last Modified

2024-11-21T04:16:16.060

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System intel xeon_d-1649n_firmware - Yes
Hardware intel xeon_d-1649n - No
Operating System intel xeon_d-1633n_firmware - Yes
Hardware intel xeon_d-1633n - No
Operating System intel xeon_d-1637_firmware - Yes
Hardware intel xeon_d-1637 - No
Operating System intel xeon_d-1627_firmware - Yes
Hardware intel xeon_d-1627 - No
Operating System intel xeon_d-1623n_firmware - Yes
Hardware intel xeon_d-1623n - No
Operating System intel xeon_d-1622_firmware - Yes
Hardware intel xeon_d-1622 - No
Operating System intel xeon_d-1653n_firmware - Yes
Hardware intel xeon_d-1653n - No
Operating System intel xeon_d-1602_firmware - Yes
Hardware intel xeon_d-1602 - No
Operating System intel xeon_d-2141i_firmware - Yes
Hardware intel xeon_d-2141i - No
Operating System intel xeon_d-2177nt_firmware - Yes
Hardware intel xeon_d-2177nt - No
Operating System intel xeon_d-2161i_firmware - Yes
Hardware intel xeon_d-2161i - No
Operating System intel xeon_d-2143it_firmware - Yes
Hardware intel xeon_d-2143it - No
Operating System intel xeon_d-2146nt_firmware - Yes
Hardware intel xeon_d-2146nt - No
Operating System intel xeon_d-2145nt_firmware - Yes
Hardware intel xeon_d-2145nt - No
Operating System intel xeon_d-2123it_firmware - Yes
Hardware intel xeon_d-2123it - No
Operating System intel xeon_d-2173it_firmware - Yes
Hardware intel xeon_d-2173it - No
Operating System intel xeon_d-2191_firmware - Yes
Hardware intel xeon_d-2191 - No
Operating System intel xeon_d-2187nt_firmware - Yes
Hardware intel xeon_d-2187nt - No
Operating System intel xeon_d-2142it_firmware - Yes
Hardware intel xeon_d-2142it - No
Operating System intel xeon_d-2163it_firmware - Yes
Hardware intel xeon_d-2163it - No
Operating System intel xeon_d-2183it_firmware - Yes
Hardware intel xeon_d-2183it - No
Operating System intel xeon_d-2166nt_firmware - Yes
Hardware intel xeon_d-2166nt - No
Operating System intel xeon_d-1513n_firmware - Yes
Hardware intel xeon_d-1513n - No
Operating System intel xeon_d-1533n_firmware - Yes
Hardware intel xeon_d-1533n - No
Operating System intel xeon_d-1553n_firmware - Yes
Hardware intel xeon_d-1553n - No
Operating System intel xeon_d-1523n_firmware - Yes
Hardware intel xeon_d-1523n - No
Operating System intel xeon_d-1543n_firmware - Yes
Hardware intel xeon_d-1543n - No
Operating System intel xeon_d-1559_firmware - Yes
Hardware intel xeon_d-1559 - No
Operating System intel xeon_d-1529_firmware - Yes
Hardware intel xeon_d-1529 - No
Operating System intel xeon_d-1539_firmware - Yes
Hardware intel xeon_d-1539 - No
Operating System intel xeon_d-1567_firmware - Yes
Hardware intel xeon_d-1567 - No
Operating System intel xeon_d-1557_firmware - Yes
Hardware intel xeon_d-1557 - No
Operating System intel xeon_d-1577_firmware - Yes
Hardware intel xeon_d-1577 - No
Operating System intel xeon_d-1571_firmware - Yes
Hardware intel xeon_d-1571 - No
Operating System intel xeon_d-1528_firmware - Yes
Hardware intel xeon_d-1528 - No
Operating System intel xeon_d-1541_firmware - Yes
Hardware intel xeon_d-1541 - No
Operating System intel xeon_d-1518_firmware - Yes
Hardware intel xeon_d-1518 - No
Operating System intel xeon_d-1521_firmware - Yes
Hardware intel xeon_d-1521 - No
Operating System intel xeon_d-1531_firmware - Yes
Hardware intel xeon_d-1531 - No
Operating System intel xeon_d-1548_firmware - Yes
Hardware intel xeon_d-1548 - No
Operating System intel xeon_d-1527_firmware - Yes
Hardware intel xeon_d-1527 - No
Operating System intel xeon_d-1537_firmware - Yes
Hardware intel xeon_d-1537 - No
Operating System intel xeon_d-1540_firmware - Yes
Hardware intel xeon_d-1540 - No
Operating System intel xeon_d-1520_firmware - Yes
Hardware intel xeon_d-1520 - No
Operating System intel xeon_platinum_processors_firmware - Yes
Hardware intel xeon_platinum_processors - No
Operating System intel xeon_gold_processors_firmware - Yes
Hardware intel xeon_gold_processors - No
Operating System intel xeon_silver_processors_firmware - Yes
Hardware intel xeon_silver_processors - No
Operating System intel xeon_bronze_processors_firmware - Yes
Hardware intel xeon_bronze_processors - No
Operating System intel server_board_s2600wf_firmware - Yes
Hardware intel server_board_s2600wf - No
Operating System intel server_board_s2600bp_firmware - Yes
Hardware intel server_board_s2600bp - No
Operating System intel server_board_s2600st_firmware - Yes
Hardware intel server_board_s2600st - No
Operating System intel server_board_s2600wt_firmware - Yes
Hardware intel server_board_s2600wt - No
Operating System intel server_board_s2600kp_firmware - Yes
Hardware intel server_board_s2600kp - No
Operating System intel server_board_s2600tp_firmware - Yes
Hardware intel server_board_s2600tp - No
Operating System intel server_board_s2600cw_firmware - Yes
Hardware intel server_board_s2600cw - No
Operating System intel server_board_s7200ap_firmware - Yes
Hardware intel server_board_s7200ap - No
Operating System intel server_board_s1200sp_firmware - Yes
Hardware intel server_board_s1200sp - No
Operating System intel server_system_s9200wk_firmware - Yes
Hardware intel server_system_s9200wk - No
Operating System intel hns2600bpq24_firmware - Yes
Hardware intel hns2600bpq24 - No
Operating System intel hns2600bps_firmware - Yes
Hardware intel hns2600bps - No
Operating System intel hns2600bps24_firmware - Yes
Hardware intel hns2600bps24 - No
Operating System intel hns7200ap_firmware - Yes
Hardware intel hns7200ap - No
Operating System intel hns7200apl_firmware - Yes
Hardware intel hns7200apl - No
Operating System intel hns7200apr_firmware - Yes
Hardware intel hns7200apr - No
Operating System intel hns7200aprl_firmware - Yes
Hardware intel hns7200aprl - No
Operating System intel hns2600tp_firmware - Yes
Hardware intel hns2600tp - No
Operating System intel hns2600tp24r_firmware - Yes
Hardware intel hns2600tp24r - No
Operating System intel hns2600tp24sr_firmware - Yes
Hardware intel hns2600tp24sr - No
Operating System intel hns2600tp24str_firmware - Yes
Hardware intel hns2600tp24str - No
Operating System intel hns2600tpf_firmware - Yes
Hardware intel hns2600tpf - No
Operating System intel hns2600tpfr_firmware - Yes
Hardware intel hns2600tpfr - No
Operating System intel hns2600tpnr_firmware - Yes
Hardware intel hns2600tpnr - No
Operating System intel hns2600tpr_firmware - Yes
Hardware intel hns2600tpr - No
Operating System intel hns2600kp_firmware - Yes
Hardware intel hns2600kp - No
Operating System intel hns2600kpf_firmware - Yes
Hardware intel hns2600kpf - No
Operating System intel hns2600kpfr_firmware - Yes
Hardware intel hns2600kpfr - No
Operating System intel hns2600kpr_firmware - Yes
Hardware intel hns2600kpr - No
Operating System intel hns2600bpb24_firmware - Yes
Hardware intel hns2600bpb24 - No
Operating System intel hns2600bpb_firmware - Yes
Hardware intel hns2600bpb - No
Operating System intel hns2600bpblc_firmware - Yes
Hardware intel hns2600bpblc - No
Operating System intel hns2600bpblc24_firmware - Yes
Hardware intel hns2600bpblc24 - No
Operating System intel hns2600bpq_firmware - Yes
Hardware intel hns2600bpq - No
Operating System intel hns2400lp_firmware - Yes
Hardware intel hns2400lp - No
Operating System intel hns2600jf_firmware - Yes
Hardware intel hns2600jf - No
Operating System intel hns2600jff_firmware - Yes
Hardware intel hns2600jff - No
Operating System intel hns2600jfq_firmware - Yes
Hardware intel hns2600jfq - No
Operating System intel hns2600wp_firmware - Yes
Hardware intel hns2600wp - No
Operating System intel hns2600wpf_firmware - Yes
Hardware intel hns2600wpf - No
Operating System intel hns2600wpq_firmware - Yes
Hardware intel hns2600wpq - No
Operating System intel mfs2600ki_firmware - Yes
Hardware intel mfs2600ki - No
Operating System intel mfs5000si_firmware - Yes
Hardware intel mfs5000si - No
Operating System intel mfs5520vir_firmware - Yes
Hardware intel mfs5520vir - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For intel's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.