Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Converged_security_management_engine_firmware | Intel | 11.0 (including) | 11.8.60 (excluding) |
Converged_security_management_engine_firmware | Intel | 11.10 (including) | 11.11.60 (excluding) |
Converged_security_management_engine_firmware | Intel | 11.20 (including) | 11.22.60 (excluding) |
Converged_security_management_engine_firmware | Intel | 12.0.0 (including) | 12.0.20 (excluding) |
Server_platform_services_firmware | Intel | * | sps_e5_04.00.04.393.0 (excluding) |