CVE Vulnerabilities

CVE-2019-0098

Published: May 17, 2019 | Modified: Nov 21, 2024
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Affected Software

NameVendorStart VersionEnd Version
Converged_security_management_engine_firmwareIntel11.0 (including)11.8.65 (excluding)
Converged_security_management_engine_firmwareIntel11.10 (including)11.11.65 (excluding)
Converged_security_management_engine_firmwareIntel11.20 (including)11.22.65 (excluding)
Converged_security_management_engine_firmwareIntel12.0 (including)12.0.35 (excluding)
Trusted_execution_engine_firmwareIntel3.0 (including)3.1.65 (excluding)
Trusted_execution_engine_firmwareIntel4.0 (including)4.0.15 (excluding)

References