Vulnerabilities > Intel > Converged Security Management Engine Firmware

DATE CVE VULNERABILITY TITLE RISK
2019-03-14 CVE-2018-12196 Improper Input Validation vulnerability in Intel Converged Security Management Engine Firmware 12.0.5
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access.
local
low complexity
intel CWE-20
4.6
2019-03-14 CVE-2018-12192 Improper Authentication vulnerability in Intel products
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.
local
low complexity
intel CWE-287
7.2
2019-03-14 CVE-2018-12191 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
local
low complexity
intel CWE-119
7.2
2019-03-14 CVE-2018-12190 Improper Input Validation vulnerability in Intel products
Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access.
local
low complexity
intel CWE-20
4.6
2019-03-14 CVE-2018-12189 Improper Check for Unusual or Exceptional Conditions vulnerability in Intel products
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
local
low complexity
intel CWE-754
2.1
2019-03-14 CVE-2018-12188 Improper Input Validation vulnerability in Intel products
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.
local
low complexity
intel CWE-20
2.1
2019-03-14 CVE-2018-12185 Improper Input Validation vulnerability in Intel Converged Security Management Engine Firmware 12.0.5
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
local
low complexity
intel CWE-20
4.6
2018-09-12 CVE-2018-3659 Unspecified vulnerability in Intel products
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
local
low complexity
intel
4.6
2018-09-12 CVE-2018-3658 Missing Release of Resource after Effective Lifetime vulnerability in multiple products
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
network
low complexity
siemens intel CWE-772
5.3
2018-09-12 CVE-2018-3657 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
local
low complexity
siemens intel CWE-119
6.7