Vulnerabilities > Intel > Converged Security Management Engine Firmware > 11.11.55

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-11087 Improper Input Validation vulnerability in Intel products
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.
local
low complexity
intel CWE-20
4.6
2019-12-18 CVE-2019-0169 Out-of-bounds Write vulnerability in Intel products
Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access.
low complexity
intel CWE-787
5.8
2019-05-17 CVE-2019-0098 Unspecified vulnerability in Intel products
Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
local
low complexity
intel
7.2
2019-03-14 CVE-2018-12191 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
local
low complexity
intel CWE-119
7.2