Lucene search

K

Intel(R) Converged Security And Management Engine (CSME) And Intel(R) Server Platform Services Firmware Security Vulnerabilities

cve
cve

CVE-2020-8744

Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E3_05.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local...

7.8CVSS

7.5AI Score

0.0004EPSS

2020-11-12 06:15 PM
58
cve
cve

CVE-2020-0545

Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E3_04.01.04.109.0,.....

4.4CVSS

5.6AI Score

0.0004EPSS

2020-06-15 02:15 PM
42
cve
cve

CVE-2018-12190

Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local...

6.7CVSS

6.7AI Score

0.0004EPSS

2019-03-14 08:29 PM
26
cve
cve

CVE-2018-12199

Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical...

6.2CVSS

6.9AI Score

0.0004EPSS

2019-03-14 08:29 PM
20
cve
cve

CVE-2018-12188

Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical...

4.6CVSS

5.5AI Score

0.001EPSS

2019-03-14 08:29 PM
25
cve
cve

CVE-2018-12192

Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical...

6.8CVSS

6.8AI Score

0.001EPSS

2019-03-14 08:29 PM
25
cve
cve

CVE-2018-12196

Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local...

6.7CVSS

6.9AI Score

0.0004EPSS

2019-03-14 08:29 PM
24
cve
cve

CVE-2018-12185

Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical...

6.8CVSS

7.1AI Score

0.001EPSS

2019-03-14 08:29 PM
28
cve
cve

CVE-2018-12191

Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute...

7.6CVSS

7.4AI Score

0.004EPSS

2019-03-14 08:29 PM
24
cve
cve

CVE-2018-12189

Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local...

4.4CVSS

5.2AI Score

0.0004EPSS

2019-03-14 08:29 PM
22
cve
cve

CVE-2018-12208

Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via...

7.6CVSS

7.7AI Score

0.004EPSS

2019-03-14 08:29 PM
21
cve
cve

CVE-2018-3655

A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical...

7.3CVSS

6.4AI Score

0.003EPSS

2018-09-12 07:29 PM
23
cve
cve

CVE-2018-3643

A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with...

8.2CVSS

8.1AI Score

0.001EPSS

2018-09-12 07:29 PM
20
2