CVE-2020-0542 is a high-severity vulnerability affecting Intel Converged Security and Management Engine (CSME) firmware versions prior to 12.0.64, 13.0.32, 14.0.33, and 14.5.12. It stems from improper buffer restrictions, allowing an authenticated local user to potentially achieve escalation of privilege, information disclosure, or denial of service. With a CVSS score of 7.8 (High), this vulnerability requires local access and low privileges, but does not rely on user interaction. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in CISA's KEV catalog, indicating no active exploitation. Community discussion and media coverage are minimal, suggesting limited public awareness or active threat intelligence.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 11.0, < 11.8.77CPE matchmatch criteria | cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* | ||
>= 11.10, < 11.12.77CPE matchmatch criteria | cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* | ||
>= 11.20, < 11.22.77CPE matchmatch criteria | cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* | ||
>= 12.0, < 12.0.64CPE matchmatch criteria | cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:undefined | ||
>= 13.0, < 13.0.32CPE matchmatch criteria | cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.