Intel Converged Security Management Engine Firmware vulnerabilities

44 known vulnerabilities affecting intel/converged_security_management_engine_firmware.

Total CVEs
44
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH15MEDIUM28

Vulnerabilities

Page 3 of 3
CVE-2018-3658MEDIUMCVSS 5.3≥ 11.0.0, < 12.0.52018-09-12
CVE-2018-3658 [MEDIUM] CWE-772 CVE-2018-3658: Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauth Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
nvd
CVE-2018-3616MEDIUMCVSS 5.9≥ 11.0.0, < 12.0.52018-09-12
CVE-2018-3616 [MEDIUM] CVE-2018-3616: Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Tec Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.
nvd
CVE-2018-3657MEDIUMCVSS 6.7≥ 11.0.0, < 12.0.52018-09-12
CVE-2018-3657 [MEDIUM] CWE-119 CVE-2018-3657: Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may all Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
nvd
CVE-2018-3627HIGHCVSS 8.2v11.02018-07-10
CVE-2018-3627 [HIGH] CVE-2018-3627: Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitr Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access.
nvd