CVE-2019-0090 is an insufficient access control vulnerability affecting Intel CSME, TXE, and Server Platform Services. It allows an unauthenticated attacker with physical access to potentially escalate privileges. The vulnerability has a CVSS score of 7.1 (HIGH), indicating a severe impact with high confidentiality, integrity, and availability compromise, despite requiring physical access and having high attack complexity. While there is no evidence of active exploitation or public exploit code, the vulnerability has garnered significant community attention and media coverage, with researchers noting its unpatchable nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 12.0.35CPE matchmatch criteria | cpe:2.3:a:intel:converged_security_and_management_engine:*:*:*:*:*:*:*:* | ||
< sps_e3_05.00.04.027.0CPE matchmatch criteria | cpe:2.3:a:intel:server_platform_services:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.3 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.