CVSS3
Attack Vector
LOCAL
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
AI Score
Confidence
Low
EPSS
Percentile
9.0%
Intel has informed HP of potential security vulnerabilities in the Intel® Converged Security Management Engine (CSME) installer and Intel® Local Manageability Service software which may allow escalation of privilege or information disclosure. Intel is releasing updates to mitigate these potential vulnerabilities.
Intel has released updates to mitigate the potential vulnerabilities. HP has identified affected platforms and corresponding SoftPaqs with minimum versions that mitigate the potential vulnerabilities. See the affected platforms listed below.
Vendor | Product | Version | CPE |
---|---|---|---|
hp | 340_g4_firmware | * | cpe:2.3:o:hp:340_g4_firmware:*:*:*:*:*:*:*:* |
hp | 348_g4_firmware | * | cpe:2.3:o:hp:348_g4_firmware:*:*:*:*:*:*:*:* |
hp | elite_dragonfly_13.5_inch_g3_notebook_pc_firmware | * | cpe:2.3:o:hp:elite_dragonfly_13.5_inch_g3_notebook_pc_firmware:*:*:*:*:*:*:*:* |
hp | dragonfly_folio_13.5_inch_g3_2-in-1_notebook_pc_firmware | * | cpe:2.3:o:hp:dragonfly_folio_13.5_inch_g3_2-in-1_notebook_pc_firmware:*:*:*:*:*:*:*:* |
hp | elite_dragonfly_firmware | * | cpe:2.3:o:hp:elite_dragonfly_firmware:*:*:*:*:*:*:*:* |
hp | elite_dragonfly_g2_firmware | * | cpe:2.3:o:hp:elite_dragonfly_g2_firmware:*:*:*:*:*:*:*:* |
hp | elite_dragonfly_max_firmware | * | cpe:2.3:o:hp:elite_dragonfly_max_firmware:*:*:*:*:*:*:*:* |
hp | elite_x2_1012_g2_firmware | * | cpe:2.3:o:hp:elite_x2_1012_g2_firmware:*:*:*:*:*:*:*:* |
hp | elite_x2_1013_g3_firmware | * | cpe:2.3:o:hp:elite_x2_1013_g3_firmware:*:*:*:*:*:*:*:* |
hp | elite_x2_g4_firmware | * | cpe:2.3:o:hp:elite_x2_g4_firmware:*:*:*:*:*:*:*:* |