CVE-2018-12147
13.06.2019, 16:29
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.Enginsight
Vendor | Product | Version |
---|---|---|
intel | converged_security_management_engine_firmware | 11.0 ≤ 𝑥 ≤ 11.8.50 |
intel | converged_security_management_engine_firmware | 11.10 ≤ 𝑥 ≤ 11.11.50 |
intel | converged_security_management_engine_firmware | 11.20 ≤ 𝑥 ≤ 11.21.51 |
intel | server_platform_services_firmware | 𝑥 < 4.0 |
intel | trusted_execution_engine_firmware | 3.0 ≤ 𝑥 ≤ 3.1.50 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration