{"api_version":"1","generated_at":"2026-07-23T13:27:16+00:00","cve":"CVE-2019-11133","urls":{"html":"https://cve.report/CVE-2019-11133","api":"https://cve.report/api/cve/CVE-2019-11133.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-11133","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-11133"},"summary":{"title":"CVE-2019-11133","description":"Improper access control in the Intel(R) Processor Diagnostic Tool before version 4.1.2.24 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.","state":"PUBLIC","assigner":"secure@intel.com","published_at":"2019-07-11 21:15:00","updated_at":"2023-11-07 03:02:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/bid/109096","name":"109096","refsource":"BID","tags":["Third Party Advisory","VDB Entry"],"title":"Malformed Request","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00268.html","name":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00268.html","refsource":"CONFIRM","tags":["Patch","Vendor Advisory"],"title":"INTEL-SA-00268","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.f5.com/csp/article/K90305959?utm_source=f5support&amp%3Butm_medium=RSS","name":"https://support.f5.com/csp/article/K90305959?utm_source=f5support&amp%3Butm_medium=RSS","refsource":"","tags":[],"title":"myF5","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://support.f5.com/csp/article/K90305959","name":"https://support.f5.com/csp/article/K90305959","refsource":"CONFIRM","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://support.f5.com/csp/article/K90305959?utm_source=f5support&amp;utm_medium=RSS","name":"https://support.f5.com/csp/article/K90305959?utm_source=f5support&amp;utm_medium=RSS","refsource":"CONFIRM","tags":[],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-11133","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-11133","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"11133","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"intel","cpe5":"processor_diagnostic_tool","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"11133","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"intel","cpe5":"processor_diagnostic_tool","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-11133","ASSIGNER":"secure@intel.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"Intel Corporation","product":{"product_data":[{"product_name":"Intel(R) Processor Diagnostic Tool Advisory","version":{"version_data":[{"version_value":"before 4.1.2.24"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Escalation of Privilege, Denial of Service, Information Disclosure"}]}]},"references":{"reference_data":[{"refsource":"CONFIRM","name":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00268.html","url":"https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00268.html"},{"refsource":"BID","name":"109096","url":"http://www.securityfocus.com/bid/109096"},{"refsource":"CONFIRM","name":"https://support.f5.com/csp/article/K90305959","url":"https://support.f5.com/csp/article/K90305959"},{"refsource":"CONFIRM","name":"https://support.f5.com/csp/article/K90305959?utm_source=f5support&amp;utm_medium=RSS","url":"https://support.f5.com/csp/article/K90305959?utm_source=f5support&amp;utm_medium=RSS"}]},"description":{"description_data":[{"lang":"eng","value":"Improper access control in the Intel(R) Processor Diagnostic Tool before version 4.1.2.24 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access."}]}},"nvd":{"publishedDate":"2019-07-11 21:15:00","lastModifiedDate":"2023-11-07 03:02:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:P/I:P/A:P","accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":4.6},"severity":"MEDIUM","exploitabilityScore":3.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:intel:processor_diagnostic_tool:*:*:*:*:*:*:*:*","versionEndExcluding":"4.1.2.24","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"11133","Ordinal":"149419","Title":"CVE-2019-11133","CVE":"CVE-2019-11133","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"11133","Ordinal":"1","NoteData":"Improper access control in the Intel(R) Processor Diagnostic Tool before version 4.1.2.24 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"11133","Ordinal":"2","NoteData":"2019-07-11","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"11133","Ordinal":"3","NoteData":"2019-10-09","Type":"Other","Title":"Modified"}]}}}