Vulnerabilities > Intel

DATE CVE VULNERABILITY TITLE RISK
2019-12-18 CVE-2019-11101 Improper Input Validation vulnerability in Intel products
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-20
4.4
2019-12-18 CVE-2019-11100 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via physical access.
low complexity
intel CWE-20
4.6
2019-12-18 CVE-2019-11097 Incorrect Default Permissions vulnerability in Intel Trusted Execution Engine Firmware
Improper directory permissions in the installer for Intel(R) Management Engine Consumer Driver for Windows before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45,13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-276
7.8
2019-12-18 CVE-2019-11090 Race Condition vulnerability in Intel products
Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPS_E5_04.01.04.305.0, SPS_SoC-X_04.00.04.108.0, SPS_SoC-A_04.00.04.191.0, SPS_E3_04.01.04.086.0, SPS_E3_04.08.04.047.0 may allow an unauthenticated user to potentially enable information disclosure via network access.
network
high complexity
intel CWE-362
5.9
2019-12-18 CVE-2019-11088 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in subsystem in Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.
low complexity
intel CWE-20
8.8
2019-12-18 CVE-2019-11087 Improper Input Validation vulnerability in Intel products
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege, information disclosure or denial of service via local access.
local
low complexity
intel CWE-20
6.7
2019-12-18 CVE-2019-11086 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in subsystem for Intel(R) AMT before version 12.0.45 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
low complexity
intel CWE-20
6.8
2019-12-18 CVE-2019-0169 Out-of-bounds Write vulnerability in Intel products
Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user to potentially enable escalation of privileges, information disclosure or denial of service via adjacent access.
low complexity
intel CWE-787
8.8
2019-12-18 CVE-2019-0168 Improper Input Validation vulnerability in Intel products
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel CWE-20
4.4
2019-12-18 CVE-2019-0166 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation in the subsystem for Intel(R) AMT before versions 11.8.70, 11.11.70, 11.22.70 and 12.0.45 may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-20
7.5