Vulnerabilities > Intel

DATE CVE VULNERABILITY TITLE RISK
2019-05-17 CVE-2019-0094 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable denial of service via adjacent network access.
low complexity
intel CWE-20
4.3
2019-05-17 CVE-2019-0093 Unspecified vulnerability in Intel Converged Security and Management Engine
Insufficient data sanitization vulnerability in HECI subsystem for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow a privileged user to potentially enable information disclosure via local access.
local
low complexity
intel
4.4
2019-05-17 CVE-2019-0092 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Insufficient input validation vulnerability in subsystem for Intel(R) AMT before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
low complexity
intel CWE-20
6.8
2019-05-17 CVE-2019-0091 Code Injection vulnerability in Intel products
Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-94
7.8
2019-05-17 CVE-2019-0090 Unspecified vulnerability in Intel products
Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
high complexity
intel
7.1
2019-05-17 CVE-2019-0089 Data Processing Errors vulnerability in Intel Server Platform Services
Improper data sanitization vulnerability in subsystem in Intel(R) SPS before versions SPS_E5_04.00.04.381.0, SPS_E3_04.01.04.054.0, SPS_SoC-A_04.00.04.181.0, and SPS_SoC-X_04.00.04.086.0 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-19
6.7
2019-05-17 CVE-2019-0086 Incorrect Permission Assignment for Critical Resource vulnerability in Intel products
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2019-05-17 CVE-2018-3701 Incorrect Permission Assignment for Critical Resource vulnerability in Intel Proset/Wireless Wifi
Improper directory permissions in the installer for Intel(R) PROSet/Wireless WiFi Software version 20.100 and earlier may allow an authenticated user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-732
7.8
2019-04-17 CVE-2019-0163 Improper Input Validation vulnerability in Intel I5-5350U Firmware
Insufficient input validation in system firmware for Intel(R) Broadwell U i5 vPro before version MYBDWi5v.86A may allow an authenticated user to potentially enable escalation of privilege, denial of service, and/or information disclosure via local access.
local
low complexity
intel CWE-20
8.2
2019-04-17 CVE-2019-0162 Unspecified vulnerability in Intel -
Memory access in virtual memory mapping for some microprocessors may allow an authenticated user to potentially enable information disclosure via local access.
local
low complexity
intel
3.8