Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4.0.25 may allow an unauthenticated user to potentially enable information disclosure via network access.
2020-06-15T14:15:10.783
2024-11-21T04:53:41.603
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:P/I:N/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | intel | converged_security_management_engine_firmware | < 11.8.77 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 11.12.77 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 11.22.77 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 12.0.64 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 13.0.32 | Yes |
Operating System | intel | converged_security_management_engine_firmware | < 14.0.33 | Yes |
Operating System | intel | trusted_execution_engine_firmware | < 3.1.75 | Yes |
Operating System | intel | trusted_execution_engine_firmware | < 4.0.25 | Yes |