Unrated severityNVD Advisory· Published Jul 14, 2021· Updated Aug 4, 2024
CVE-2019-11098
CVE-2019-11098
Description
Insufficient input validation in MdeModulePkg in EDKII may allow an unauthenticated user to potentially enable escalation of privilege, denial of service and/or information disclosure via physical access.
Affected products
20- EDKII/MdeModulePkgdescription
- osv-coords19 versionspkg:rpm/opensuse/ovmf&distro=openSUSE%20Leap%20Micro%205.2pkg:rpm/suse/ovmf&distro=SUSE%20Enterprise%20Storage%207pkg:rpm/suse/ovmf&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP2-LTSSpkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-ESPOSpkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP3pkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP2-LTSSpkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP2pkg:rpm/suse/ovmf&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/ovmf&distro=SUSE%20Manager%20Proxy%204.1pkg:rpm/suse/ovmf&distro=SUSE%20Manager%20Proxy%204.2pkg:rpm/suse/ovmf&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.1pkg:rpm/suse/ovmf&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.2pkg:rpm/suse/ovmf&distro=SUSE%20Manager%20Server%204.1pkg:rpm/suse/ovmf&distro=SUSE%20Manager%20Server%204.2
< 202008-150300.10.17.1+ 18 more
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 201911-150200.7.24.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 201911-150200.7.24.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 201911-150200.7.24.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 201911-150200.7.24.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 201911-150200.7.24.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 201911-150200.7.24.1
- (no CPE)range: < 202008-150300.10.17.1
- (no CPE)range: < 201911-150200.7.24.1
- (no CPE)range: < 202008-150300.10.17.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- edk2-docs.gitbook.io/security-advisory/bootguard-toctou-vulnerabilitymitrex_refsource_MISC
News mentions
0No linked articles in our index yet.