← Back

Converged Security Management Engine Firmware

converged_security_management_engine_firmware

Vendor: Intel • 44 CVEs

CVEs (44)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
Dec 18, 2019
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privi...Show more
Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access.Show less
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
Dec 18, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information...Show more
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.Show less
1Intel
1Converged Security Management Engine Firmware
Nov 21, 2024
Dec 18, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.
1Intel
3Converged Security Management Engine Firmware
Server Platform Services FirmwareTrusted Execution Engine Firmware
Nov 21, 2024
Jun 13, 2019
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a...Show more
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.Show less
1Intel
1Converged Security Management Engine Firmware
Nov 21, 2024
May 17, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Buffer overflow in subsystem in Intel(R) DAL before version 12.0.35 may allow a privileged user to potentially enable escalation of privilege via local access.
1Intel
1Converged Security Management Engine Firmware
Nov 21, 2024
May 17, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of privilege via network access.
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
May 17, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
May 17, 2019
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to po...Show more
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.Show less
1Intel
3Converged Security Management Engine Firmware
Server Platform Services FirmwareTrusted Execution Engine Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
7.6 HIGH· v3
4.6 MEDIUM· v2
Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012...Show more
Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.Show less
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
6.2 MEDIUM· v3
7.2 HIGH· v2
Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via...Show more
Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.Show less
1Intel
1Converged Security Management Engine Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access.
1Intel
2Converged Security Management Engine Firmware
Server Platform Services Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentiall...Show more
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.Show less
1Intel
3Converged Security Management Engine Firmware
Server Platform Services FirmwareTrusted Execution Engine Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
7.6 HIGH· v3
7.2 HIGH· v2
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3...Show more
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.Show less
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of p...Show more
Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access.Show less
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local...Show more
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.Show less
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
4.6 MEDIUM· v3
2.1 LOW· v2
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical ac...Show more
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.Show less
1Intel
1Converged Security Management Engine Firmware
Nov 21, 2024
Mar 14, 2019
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
1Intel
2Converged Security Management Engine Firmware
Trusted Execution Engine Firmware
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.8 MEDIUM· v3
4.6 MEDIUM· v2
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
2Intel
Siemens
14Active Management Technology Firmware
Converged Security Management Engine FirmwareManageability Engine Firmware+11 more
Nov 21, 2024
Sep 12, 2018
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
2Intel
Siemens
14Active Management Technology Firmware
Converged Security Management Engine FirmwareManageability Engine Firmware+11 more
Nov 21, 2024
Sep 12, 2018
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.