First published: Fri May 17 2019(Updated: )
Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security And Management Engine | <12.0.35 | |
Intel Server Platform Services | <sps_e3_05.00.04.027.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2019-0090 is high, with a severity value of 7.1.
The affected software for CVE-2019-0090 includes Intel Converged Security And Management Engine versions up to 12.0.35 and Intel Server Platform Services version up to sps_e3_05.00.04.027.0.
The vulnerability in CVE-2019-0090 is an insufficient access control vulnerability in subsystems for Intel(R) CSME, Intel(R) TXE, Intel(R) Server Platform Services, and Intel(R) SPS.
An unauthenticated user can potentially exploit CVE-2019-0090 to enable escalation of privilege.
You can find more information about CVE-2019-0090 in the following references: [Link 1](https://support.f5.com/csp/article/K59145983) and [Link 2](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html).