7.2
CVE-2019-0098
- EPSS 0.17%
- Veröffentlicht 17.05.2019 16:29:01
- Zuletzt bearbeitet 21.11.2024 04:16:13
- Quelle secure@intel.com
- CVE-Watchlists
- Unerledigt
Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Converged Security Management Engine Firmware Version >= 11.0 < 11.8.65
Intel ≫ Converged Security Management Engine Firmware Version >= 11.10 < 11.11.65
Intel ≫ Converged Security Management Engine Firmware Version >= 11.20 < 11.22.65
Intel ≫ Converged Security Management Engine Firmware Version >= 12.0 < 12.0.35
Intel ≫ Trusted Execution Engine Firmware Version >= 3.0 < 3.1.65
Intel ≫ Trusted Execution Engine Firmware Version >= 4.0 < 4.0.15
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.17% | 0.383 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 0.9 | 5.9 |
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|