CVE-2019-11090: Intel Platform Trust Technology Firmware
Medium severity, CVSS 5.9. EPSS: 2.7% chance of exploitation in the next 30 days.
Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, SPS_E3_04.01.04.086.0, SPS_E3_04.08.04.047.0 may allow an unauthenticated user to potentially enable information disclosure via network access.
Affected products
- Intel Platform Trust Technology Firmware: from 11.0, up to and including 11.8.70; from 11.10, before 11.11.70 (fixed in 11.11.70); from 11.20, before 11.22.70 (fixed in 11.22.70); from 12.0, before 12.0.45 (fixed in 12.0.45); from 13.0, before 13.0.0 (fixed in 13.0.0); from 14.0.0, before 14.0.10 (fixed in 14.0.10)
- Intel Server Platform Services Firmware: any version; from sps_e3_04.01.00.000.0, before sps_e3_04.01.04.086.0 (fixed in sps_e3_04.01.04.086.0); from sps_e5_04.00.00.000.0, before sps_e5_04.01.04.305.0 (fixed in sps_e5_04.01.04.305.0); from sps_soc-a_04.00.00.000.0, before sps_soc-a_04.00.04.191.0 (fixed in sps_soc-a_04.00.04.191.0); from sps_soc-x_04.00.00.000.0, before sps_soc-x_04.00.04.108.0 (fixed in sps_soc-x_04.00.04.108.0)
- Intel Trusted Execution Engine Firmware: from 3.0, before 3.1.70 (fixed in 3.1.70); from 4.0, before 4.0.20 (fixed in 4.0.20)
Published 2019-12-18. Last modified 2026-06-17.