Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
2019-12-18T22:15:11.847
2024-11-21T04:16:23.760
Modified
CVSSv3.1: 4.4 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:N/A:N
3.9
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | intel | converged_security_management_engine_firmware | < 11.8.70 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 12.0.45 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 13.0.10 | Yes |
Operating System | intel | trusted_execution_engine_firmware | < 3.1.70 | Yes |
Operating System | intel | trusted_execution_engine_firmware | < 4.0.20 | Yes |