Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
converged security management engine firmware vulnerabilities and exploits
(subscribe to this query)
4.6
CVSSv2
CVE-2019-11110
Authentication bypass in the subsystem for Intel(R) CSME prior to 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE prior to 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.
Intel Converged Security Management Engine Firmware
Intel Trusted Execution Engine Firmware
2.1
CVSSv2
CVE-2018-12189
Unhandled exception in Content Protection subsystem in Intel CSME prior to 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE prior to 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
Intel Trusted Execution Engine Firmware
Intel Converged Security Management Engine Firmware
7.2
CVSSv2
CVE-2018-12199
Buffer overflow in an OS component in Intel CSME prior to 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version prior to 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.
Intel Trusted Execution Engine Firmware
Intel Converged Security Management Engine Firmware
4.6
CVSSv2
CVE-2019-11104
Insufficient input validation in MEInfo software for Intel(R) CSME prior to 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE prior to 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.
Intel Converged Security Management Engine Firmware
Intel Trusted Execution Engine Firmware
2.1
CVSSv2
CVE-2018-12188
Insufficient input validation in Intel CSME prior to 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.
Intel Converged Security Management Engine Firmware
Intel Trusted Execution Engine Firmware
4.6
CVSSv2
CVE-2018-12190
Insufficient input validation in Intel(r) CSME subsystem prior to 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE prior to 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access.
Intel Trusted Execution Engine Firmware
Intel Converged Security Management Engine Firmware
4.6
CVSSv2
CVE-2019-0086
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME prior to 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
Intel Converged Security Management Engine Firmware
Intel Trusted Execution Engine Firmware
7.2
CVSSv2
CVE-2019-0098
Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE prior to 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Intel Converged Security Management Engine Firmware
Intel Trusted Execution Engine Firmware
4.6
CVSSv2
CVE-2018-3643
A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker ...
Intel Server Platform Services Firmware
Intel Converged Security Management Engine Firmware
7.2
CVSSv2
CVE-2018-12192
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.
Intel Server Platform Services Firmware
Intel Converged Security Management Engine Firmware
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
NEXT »