Intel Trusted Execution Engine Firmware vulnerabilities
27 known vulnerabilities affecting intel/trusted_execution_engine_firmware.
Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM16
Vulnerabilities
Page 2 of 2
CVE-2018-12190MEDIUMCVSS 6.7≥ 3.0, < 3.1.60≥ 4.0, < 4.0.102019-03-14
CVE-2018-12190 [MEDIUM] CWE-20 CVE-2018-12190: Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60
Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access.
nvd
CVE-2018-12188MEDIUMCVSS 4.6≥ 3.0, < 3.1.60≥ 4.0, < 4.0.102019-03-14
CVE-2018-12188 [MEDIUM] CWE-20 CVE-2018-12188: Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 o
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.
nvd
CVE-2018-12189MEDIUMCVSS 4.4≥ 3.0, < 3.1.60≥ 4.0, < 4.0.102019-03-14
CVE-2018-12189 [MEDIUM] CWE-754 CVE-2018-12189: Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60,
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
nvd
CVE-2018-3655HIGHCVSS 7.3≥ 3.0, ≤ 3.1.502018-09-12
CVE-2018-3655 [HIGH] CVE-2018-3655: A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
nvd
CVE-2018-3659MEDIUMCVSS 6.8fixed in 4.02018-09-12
CVE-2018-3659 [MEDIUM] CVE-2018-3659: A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmw
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
nvd
CVE-2017-5710HIGHCVSS 7.8v3.02017-11-21
CVE-2017-5710 [HIGH] CVE-2017-5710: Multiple privilege escalations in kernel in Intel Trusted Execution Engine Firmware 3.0 allows unaut
Multiple privilege escalations in kernel in Intel Trusted Execution Engine Firmware 3.0 allows unauthorized process to access privileged content via unspecified vector.
nvd
CVE-2017-5707HIGHCVSS 7.8v3.02017-11-21
CVE-2017-5707 [HIGH] CWE-119 CVE-2017-5707: Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker wi
Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.
nvd
← Previous2 / 2