Vulnerabilities > Intel > Converged Security Management Engine Firmware > 11.8.50
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-14 | CVE-2018-12191 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access. | 7.6 |
2019-03-14 | CVE-2018-12190 | Improper Input Validation vulnerability in Intel products Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access. | 6.7 |
2019-03-14 | CVE-2018-12189 | Improper Check for Unusual or Exceptional Conditions vulnerability in Intel products Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access. | 4.4 |
2019-03-14 | CVE-2018-12188 | Improper Input Validation vulnerability in Intel products Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access. | 4.6 |
2019-03-14 | CVE-2018-12185 | Improper Input Validation vulnerability in Intel Converged Security Management Engine Firmware Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access. | 6.8 |
2018-09-12 | CVE-2018-3659 | Unspecified vulnerability in Intel products A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access. low complexity intel | 6.8 |
2018-09-12 | CVE-2018-3655 | Unspecified vulnerability in Intel products A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access. low complexity intel | 7.3 |
2018-09-12 | CVE-2018-3643 | Unspecified vulnerability in Intel products A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with administrative privileges to uncover certain platform secrets via local access or to potentially execute arbitrary code. | 8.2 |