CVE Vulnerabilities

CVE-2020-0542

Published: Jun 15, 2020 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Improper buffer restrictions in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an authenticated user to potentially enable escalation of privilege, information disclosure or denial of service via local access.

Affected Software

NameVendorStart VersionEnd Version
Converged_security_management_engine_firmwareIntel11.0 (including)11.8.77 (excluding)
Converged_security_management_engine_firmwareIntel11.10 (including)11.12.77 (excluding)
Converged_security_management_engine_firmwareIntel11.20 (including)11.22.77 (excluding)
Converged_security_management_engine_firmwareIntel12.0 (including)12.0.64 (excluding)
Converged_security_management_engine_firmwareIntel13.0 (including)13.0.32 (excluding)
Converged_security_management_engine_firmwareIntel14.0 (including)14.0.33 (excluding)
Converged_security_management_engine_firmwareIntel14.5.11 (including)14.5.11 (including)

References