Vulnerabilities > Intel > Converged Security Management Engine Firmware
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-03-14 | CVE-2018-12196 | Improper Input Validation vulnerability in Intel Converged Security Management Engine Firmware Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access. | 6.7 |
2019-03-14 | CVE-2018-12192 | Improper Authentication vulnerability in Intel products Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access. | 6.8 |
2019-03-14 | CVE-2018-12191 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access. | 7.6 |
2019-03-14 | CVE-2018-12190 | Improper Input Validation vulnerability in Intel products Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access. | 6.7 |
2019-03-14 | CVE-2018-12189 | Improper Check for Unusual or Exceptional Conditions vulnerability in Intel products Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access. | 4.4 |
2019-03-14 | CVE-2018-12188 | Improper Input Validation vulnerability in Intel products Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access. | 4.6 |
2019-03-14 | CVE-2018-12185 | Improper Input Validation vulnerability in Intel Converged Security Management Engine Firmware Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access. | 6.8 |
2018-09-12 | CVE-2018-3659 | Unspecified vulnerability in Intel products A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access. low complexity intel | 6.8 |
2018-09-12 | CVE-2018-3658 | Missing Release of Resource after Effective Lifetime vulnerability in multiple products Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access. | 5.3 |
2018-09-12 | CVE-2018-3657 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access. | 6.7 |