Vulnerabilities > Intel > Trusted Execution Engine Firmware > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-05-17 | CVE-2019-0098 | Unspecified vulnerability in Intel products Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. low complexity intel | 6.8 |
2019-03-14 | CVE-2018-12199 | Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access. | 6.2 |
2019-03-14 | CVE-2018-12190 | Improper Input Validation vulnerability in Intel products Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access. | 6.7 |
2019-03-14 | CVE-2018-12189 | Improper Check for Unusual or Exceptional Conditions vulnerability in Intel products Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access. | 4.4 |
2019-03-14 | CVE-2018-12188 | Improper Input Validation vulnerability in Intel products Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access. | 4.6 |
2018-09-12 | CVE-2018-3659 | Unspecified vulnerability in Intel products A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access. low complexity intel | 6.8 |