Converged Security Management Engine Firmware
Vendor:
First CVE: Jul 10, 2018 · Active for 8 years
44
Total CVEs
More Total CVEs than 98% of tracked products
11.0
Avg CVEs / Year
Higher CVE frequency than 97% of tracked products
6.7
Avg CVSS
Higher Avg CVSS than 38% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Converged Security Management Engine Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 10, 2018
8 years ago
Most Recent CVE
Aug 11, 2023
1,082 days ago
CVE Severity & Scoring
Converged Security Management Engine Firmware44 CVEs
64%
34%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local28 (63.6%)
Network6 (13.6%)
Unknown0 (0.0%)
Physical9 (20.5%)
Adjacent Network1 (2.3%)
Attack Complexity
Low43 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None44 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low7 (15.9%)
High22 (50.0%)
None15 (34.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (44 CVEs).
44 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-0153CRITICAL Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of privilege via network access. | May 17, 2019 | 9.8 | 29 | NO | NO |
CVE-2019-0169HIGH Heap overflow in subsystem in Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an unauthenticated user t | Dec 18, 2019 | 8.8 | 28 | NO | NO |
CVE-2018-3655HIGH A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3 | Sep 12, 2018 | 7.3 | 26 | NO | NO |
CVE-2018-3643HIGH A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.5 | Sep 12, 2018 | 8.2 | 26 | NO | NO |
CVE-2018-3627HIGH Logic bug in Intel Converged Security Management Engine 11.x may allow an attacker to execute arbitrary code via local privileged access. | Jul 10, 2018 | 8.2 | 26 | NO | NO |
CVE-2020-0536HIGH Improper input validation in the DAL subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77, 12.0.64, 13.0.32,14.0.33 and Intel(R) TXE versions before 3.1.75 and 4 | Jun 15, 2020 | 7.5 | 25 | NO | NO |
CVE-2020-0542HIGH Improper buffer restrictions in subsystem for Intel(R) CSME versions before 12.0.64, 13.0.32, 14.0.33 and 14.5.12 may allow an authenticated user to potentially enable escalation o | Jun 15, 2020 | 7.8 | 24 | NO | NO |
CVE-2019-11147HIGH Insufficient access control in hardware abstraction driver for MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0, 14.0.10; TXEInfo soft | Dec 18, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-11104HIGH Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 an | Dec 18, 2019 | 7.8 | 24 | NO | NO |
CVE-2019-0086HIGH Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0 | May 17, 2019 | 7.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (44 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (44 CVEs).
Media Mentions
Signals from CVEs in this product scope (44 CVEs).
Top CNAs Publishing CVEs For Converged Security Management Engine Firmware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 14.5.11 | 3 | 7.3 | 0.9% | 0 | 0 |
| 11.0 | 1 | 8.2 | 0.5% | 0 | 0 |