Improper input validation in the DAL subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an unauthenticated user to potentially enable denial of service via network access.
2020-06-15T14:15:10.643
2024-11-21T04:53:41.380
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | intel | converged_security_management_engine_firmware | < 12.0.64 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 13.0.32 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 14.0.33 | Yes |
Operating System | intel | converged_security_management_engine_firmware | 14.5.11 | Yes |