CVE Vulnerabilities

CVE-2019-0098

Published: May 17, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Affected Software

Name Vendor Start Version End Version
Converged_security_management_engine_firmware Intel 11.0 (including) 11.8.65 (excluding)
Converged_security_management_engine_firmware Intel 11.10 (including) 11.11.65 (excluding)
Converged_security_management_engine_firmware Intel 11.20 (including) 11.22.65 (excluding)
Converged_security_management_engine_firmware Intel 12.0 (including) 12.0.35 (excluding)
Trusted_execution_engine_firmware Intel 3.0 (including) 3.1.65 (excluding)
Trusted_execution_engine_firmware Intel 4.0 (including) 4.0.15 (excluding)

References