Vulnerabilities > Intel > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-06-15 CVE-2020-8675 Unspecified vulnerability in Intel Innovation Engine Firmware
Insufficient control flow management in firmware build and signing tool for Intel(R) Innovation Engine before version 1.0.859 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
low complexity
intel
6.8
2020-06-15 CVE-2020-8674 Out-of-bounds Read vulnerability in Intel products
Out-of-bounds read in DHCPv6 subsystem in Intel(R) AMT and Intel(R)ISM versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64 and 14.0.33 may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-125
5.3
2020-06-15 CVE-2020-0566 Unspecified vulnerability in Intel Trusted Execution Engine Firmware
Improper Access Control in subsystem for Intel(R) TXE versions before 3.175 and 4.0.25 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
low complexity
intel
6.8
2020-06-15 CVE-2020-0545 Integer Overflow or Wraparound vulnerability in Intel products
Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0 may allow a privileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-190
4.4
2020-06-15 CVE-2020-0543 Incomplete Cleanup vulnerability in multiple products
Incomplete cleanup from specific special register read operations in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
5.5
2020-06-15 CVE-2020-0541 Out-of-bounds Write vulnerability in Intel Converged Security Management Engine Firmware
Out-of-bounds write in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a privileged user to potentially enable escalation of privilege via local access.
local
low complexity
intel CWE-787
6.7
2020-06-15 CVE-2020-0539 Path Traversal vulnerability in Intel products
Path traversal in subsystem for Intel(R) DAL software for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32, 14.0.33 and Intel(R) TXE versions before 3.1.75, 4.0.25 may allow an unprivileged user to potentially enable denial of service via local access.
local
low complexity
intel CWE-22
5.5
2020-06-15 CVE-2020-0537 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Improper input validation in subsystem for Intel(R) AMT versions before 11.8.77, 11.12.77, 11.22.77 and 12.0.64 may allow a privileged user to potentially enable denial of service via network access.
network
low complexity
intel CWE-20
4.9
2020-06-15 CVE-2020-0535 Improper Input Validation vulnerability in Intel Active Management Technology Firmware
Improper input validation in Intel(R) AMT versions before 11.8.76, 11.12.77, 11.22.77 and 12.0.64 may allow an unauthenticated user to potentially enable information disclosure via network access.
network
low complexity
intel CWE-20
5.3
2020-06-15 CVE-2020-0533 Inadequate Encryption Strength vulnerability in Intel Converged Security Management Engine Firmware
Reversible one-way hash in Intel(R) CSME versions before 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
local
low complexity
intel CWE-326
6.7