CVE-2019-14598

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
13/02/2020
Last modified:
01/01/2022

Description

Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:-:*:*:* 12.0 (including) 12.0.48 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:iot:*:*:* 12.0 (including) 12.0.56 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:-:*:*:* 13.0 (including) 13.0.20 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:-:*:*:* 14.0 (including) 14.0.10 (excluding)
cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*