Intel Converged Security Management Engine Firmware vulnerabilities
44 known vulnerabilities affecting intel/converged_security_management_engine_firmware.
Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM28
Vulnerabilities
Page 3 of 3
CVE-2020-0545P4MEDIUMCVSS 4.4≥ 11.0, < 11.8.77≥ 11.10, < 11.12.77+1 more2020-06-15
CVE-2020-0545 [MEDIUM] CWE-190 CVE-2020-0545: Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Inte
Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0 may allow a privileged user to po
nvd
CVE-2018-12189P4MEDIUMCVSS 4.4≥ 11.0, < 11.8.60≥ 11.10, < 11.11.60+2 more2019-03-14
CVE-2018-12189 [MEDIUM] CWE-754 CVE-2018-12189: Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60,
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
nvd
CVE-2022-38102P4MEDIUMCVSS 4.4fixed in 16.1.27fixed in 15.0.452023-08-11
CVE-2022-38102 [MEDIUM] CWE-20 CVE-2022-38102: Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine bef
Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may allow a privileged user to potentially enable denial of service via local access.
nvd
CVE-2019-0165P4MEDIUMCVSS 4.4≥ 12.0, < 12.0.45≥ 13.0, < 13.0.10+1 more2019-12-18
CVE-2019-0165 [MEDIUM] CWE-20 CVE-2019-0165: Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and
Insufficient Input validation in the subsystem for Intel(R) CSME before versions 12.0.45,13.0.10 and 14.0.10 may allow a privileged user to potentially enable denial of service via local access.
nvd
← Previous3 / 3