cbcvebase.

Intel Trusted Execution Engine Firmware vulnerabilities

27 known vulnerabilities affecting intel/trusted_execution_engine_firmware.

Total CVEs
27
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM16

Vulnerabilities

Page 2 of 2
CVE-2018-3659P4MEDIUMCVSS 6.8fixed in 4.02018-09-12
CVE-2018-3659 [MEDIUM] CVE-2018-3659: A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmw A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
nvd
CVE-2020-0539P4MEDIUMCVSS 5.5≥ 3.0, < 3.1.75≥ 4.0, < 4.0.252020-06-15
CVE-2020-0539 [MEDIUM] CWE-22 CVE-2020-0539: Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11. Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.
nvd
CVE-2018-12188P4MEDIUMCVSS 4.6≥ 3.0, < 3.1.60≥ 4.0, < 4.0.102019-03-14
CVE-2018-12188 [MEDIUM] CWE-20 CVE-2018-12188: Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 o Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.
nvd
CVE-2019-11101P4MEDIUMCVSS 4.4≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11101 [MEDIUM] CWE-20 CVE-2019-11101: Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2019-0168P4MEDIUMCVSS 4.4≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-0168 [MEDIUM] CWE-20 CVE-2019-0168: Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 an Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2019-11102P4MEDIUMCVSS 4.4≥ 3.0, < 3.1.70≥ 4.0, < 4.0.202019-12-18
CVE-2019-11102 [MEDIUM] CWE-20 CVE-2019-11102: Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11 Insufficient input validation in Intel(R) DAL software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
nvd
CVE-2018-12189P4MEDIUMCVSS 4.4≥ 3.0, < 3.1.60≥ 4.0, < 4.0.102019-03-14
CVE-2018-12189 [MEDIUM] CWE-754 CVE-2018-12189: Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
nvd
Intel Trusted Execution Engine Firmware vulnerabilities | cvebase