Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.
2019-06-13T16:29:00.247
2024-11-21T03:44:39.373
Modified
CVSSv3.0: 6.7 (MEDIUM)
AV:L/AC:L/Au:N/C:C/I:C/A:C
3.9
10.0
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | intel | converged_security_management_engine_firmware | ≤ 11.8.50 | Yes |
Operating System | intel | converged_security_management_engine_firmware | ≤ 11.11.50 | Yes |
Operating System | intel | converged_security_management_engine_firmware | ≤ 11.21.51 | Yes |
Operating System | intel | server_platform_services_firmware | < 4.0 | Yes |
Operating System | intel | trusted_execution_engine_firmware | ≤ 3.1.50 | Yes |