CVE-2019-0111
Description
Improper file permissions for Intel(R) Data Center Manager SDK before version 5.0.2 may allow an authenticated user to potentially enable information disclosure via local access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper file permissions in Intel Data Center Manager SDK before 5.0.2 allow local authenticated users to disclose sensitive information.
Vulnerability
In Intel Data Center Manager SDK versions prior to 5.0.2, improper file permissions are set during installation or runtime, allowing an authenticated local user to access files that should be protected. This vulnerability is categorized as CWE-275 (Permission Issues) [2].
Exploitation
An attacker must have local access and be authenticated to the system. Operating with standard user privileges, the attacker can exploit the misconfigured permissions to read files belonging to the Data Center Manager SDK, potentially including configuration files or credentials. No user interaction is required beyond initial authentication [1][2].
Impact
Successful exploitation leads to information disclosure of sensitive data accessible via the SDK's files. The attacker gains access to data that may aid in further attacks, but does not achieve code execution or privilege escalation directly from this vulnerability. The CVSS v3 base score is 5.5 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) [2].
Mitigation
Intel released version 5.0.2 of the Data Center Manager SDK to address this issue. Users should update to version 5.0.2 or later. No workaround is provided. The vulnerability is not listed on CISA's Known Exploited Vulnerabilities (KEV) catalog [1][2].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1- Range: <5.0.2
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.securityfocus.com/bid/107067mitrevdb-entryx_refsource_BID
- ics-cert.us-cert.gov/advisories/ICSA-19-050-01mitrex_refsource_MISC
- www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00215.htmlmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.