CVE Vulnerabilities

CVE-2019-0098

Published: May 17, 2019 | Modified: Aug 24, 2020
CVSS 3.x
6.8
MEDIUM
Source:
NVD
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

Affected Software

Name Vendor Start Version End Version
Converged_security_management_engine_firmware Intel 11.0 (including) 11.8.65 (excluding)
Converged_security_management_engine_firmware Intel 11.10 (including) 11.11.65 (excluding)
Converged_security_management_engine_firmware Intel 11.20 (including) 11.22.65 (excluding)
Converged_security_management_engine_firmware Intel 12.0 (including) 12.0.35 (excluding)
Trusted_execution_engine_firmware Intel 3.0 (including) 3.1.65 (excluding)
Trusted_execution_engine_firmware Intel 4.0 (including) 4.0.15 (excluding)

References