Intel Trusted Execution Engine Firmware vulnerabilities
27 known vulnerabilities affecting intel/trusted_execution_engine_firmware.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM16
Vulnerabilities
Page 1 of 2
CVE-2020-0536HIGHCVSS 7.5≥ 3.0, < 3.1.75≥ 4.0, < 4.0.252020-06-15
CVE-2020-0536 [HIGH] CWE-20 CVE-2020-0536: Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77,
Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4.0.25 may allow an unauthenticated user to potentially enable information disclosure via network access.
nvd
CVE-2020-0566MEDIUMCVSS 6.8≥ 3.0, ≤ 3.1.70≥ 4.0, ≤ 4.0.202020-06-15
CVE-2020-0566 [MEDIUM] CVE-2020-0566: Improper Access Control in subsystem for Intel(R) TXE versions before 3.175 and 4.0.25 may allow an
Improper Access Control in subsystem for Intel(R) TXE versions before 3.175 and 4.0.25 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
nvd
CVE-2020-0539MEDIUMCVSS 5.5≥ 3.0, < 3.1.75≥ 4.0, < 4.0.252020-06-15
CVE-2020-0539 [MEDIUM] CWE-22 CVE-2020-0539: Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.
Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.
nvd
CVE-2019-11097HIGHCVSS 7.8≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11097 [HIGH] CWE-276 CVE-2019-11097: Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for W
Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-0169HIGHCVSS 8.8≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-0169 [HIGH] CWE-787 CVE-2019-0169: Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; In
Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access.
nvd
CVE-2019-11104HIGHCVSS 7.8≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11104 [HIGH] CWE-20 CVE-2019-11104: Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70
Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-11147HIGHCVSS 7.8≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11147 [HIGH] CVE-2019-11147: Insufficient access control in hardware abstraction driver for MEInfo software for Intel(R) CSME bef
Insufficient access control in hardware abstraction driver for MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, 14.0.10; TXEInfo software for Intel(R) TXE before versions 3.1.70 and 4.0.20; INTEL-SA-00086 Detection Tool version 1.2.7.0 or before; INTEL-SA-00125 Detection Tool version 1.0.45.0 or before may allow
nvd
CVE-2019-0168MEDIUMCVSS 4.4≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-0168 [MEDIUM] CWE-20 CVE-2019-0168: Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 an
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2019-11110MEDIUMCVSS 6.7≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11110 [MEDIUM] CVE-2019-11110: Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70
Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-11102MEDIUMCVSS 4.4≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11102 [MEDIUM] CWE-20 CVE-2019-11102: Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11
Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2019-11087MEDIUMCVSS 6.7≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11087 [MEDIUM] CWE-20 CVE-2019-11087: Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70,
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.
nvd
CVE-2019-11101MEDIUMCVSS 4.4≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11101 [MEDIUM] CWE-20 CVE-2019-11101: Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70,
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2019-11106MEDIUMCVSS 6.7≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11106 [MEDIUM] CWE-613 CVE-2019-11106: Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45,
Insufficient session validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-11090MEDIUMCVSS 5.9≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11090 [MEDIUM] CWE-362 CVE-2019-11090: Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70,
Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, SPS_E3_04.01.04.086.0, SPS_E3_04.08.04.047.0 may allow an unauthenticated u
nvd
CVE-2018-12147MEDIUMCVSS 6.7≥ 3.0, ≤ 3.1.502019-06-13
CVE-2018-12147 [MEDIUM] CWE-20 CVE-2018-12147: Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Ser
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.
nvd
CVE-2019-0086HIGHCVSS 7.8≥ 3.0, < 3.1.65≥ 4.0, ≤ 4.0.152019-05-17
CVE-2019-0086 [HIGH] CWE-59 CVE-2019-0086: Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME b
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2019-0098MEDIUMCVSS 6.8≥ 3.0, < 3.1.65≥ 4.0, < 4.0.152019-05-17
CVE-2019-0098 [MEDIUM] CVE-2019-0098: Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3
Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
nvd
CVE-2018-12191HIGHCVSS 7.6≥ 3.0, < 3.1.60≥ 4.0, < 4.0.102019-03-14
CVE-2018-12191 [HIGH] CWE-119 CVE-2018-12191: Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
nvd
CVE-2018-12208HIGHCVSS 7.6≥ 3.0, < 3.1.60≥ 4.0, < 4.0.102019-03-14
CVE-2018-12208 [HIGH] CWE-119 CVE-2018-12208: Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12
Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
nvd
CVE-2018-12199MEDIUMCVSS 6.2≥ 3.0, < 3.1.60≥ 4.0, < 4.0.102019-03-14
CVE-2018-12199 [MEDIUM] CWE-119 CVE-2018-12199: Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0
Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.
nvd
1 / 2Next →