Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
converged security management engine firmware vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv3
CVE-2020-0534
Improper input validation in the DAL subsystem for Intel(R) CSME versions prior to 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an unauthenticated user to potentially enable denial of service via network access.
Intel Converged Security Management Engine Firmware
Intel Converged Security Management Engine Firmware 14.5.11
6.7
CVSSv3
CVE-2020-0541
Out-of-bounds write in subsystem for Intel(R) CSME versions prior to 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow a privileged user to potentially enable escalation of privilege via local access.
Intel Converged Security Management Engine Firmware
Intel Converged Security Management Engine Firmware 14.5.11
7.8
CVSSv3
CVE-2020-0542
Improper buffer restrictions in subsystem for Intel(R) CSME versions prior to 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.
Intel Converged Security Management Engine Firmware
Intel Converged Security Management Engine Firmware 14.5.11
6.7
CVSSv3
CVE-2020-0533
Reversible one-way hash in Intel(R) CSME versions prior to 11.8.76, 11.12.77 and 11.22.77 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
Intel Converged Security Management Engine Firmware
6.7
CVSSv3
CVE-2019-0170
Buffer overflow in subsystem in Intel(R) DAL before version 12.0.35 may allow a privileged user to potentially enable escalation of privilege via local access.
Intel Converged Security Management Engine Firmware
7.8
CVSSv3
CVE-2019-11103
Insufficient input validation in firmware update software for Intel(R) CSME prior to 12.0.45,13.0.10 and 14.0.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
Intel Converged Security Management Engine Firmware
6.7
CVSSv3
CVE-2019-11105
Logic issue in subsystem for Intel(R) CSME prior to 12.0.45, 13.0.10 and 14.0.10 may allow a privileged user to potentially enable escalation of privilege and information disclosure via local access.
Intel Converged Security Management Engine Firmware
6.7
CVSSv3
CVE-2019-11108
Insufficient input validation in subsystem for Intel(R) CSME prior to 12.0.45 and 13.0.10 may allow a privileged user to potentially enable escalation of privilege via local access.
Intel Converged Security Management Engine Firmware
6.8
CVSSv3
CVE-2018-12185
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
Intel Converged Security Management Engine Firmware
6.7
CVSSv3
CVE-2018-12196
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access.
Intel Converged Security Management Engine Firmware
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-38028
CVE-2024-32406
CVE-2024-25624
IMAP
CVE-2024-2310
CVE-2024-0874
CVE-2024-20359
XXE
remote code execution
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
6
NEXT »