First published: Fri May 17 2019(Updated: )
Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=11.0<11.8.65 | |
Intel Converged Security Management Engine Firmware | >=11.10<11.11.65 | |
Intel Converged Security Management Engine Firmware | >=11.20<11.22.65 | |
Intel Converged Security Management Engine Firmware | >=12.0<12.0.35 | |
Intel Trusted Execution Engine Firmware | >=3.0<3.1.65 | |
Intel Trusted Execution Engine Firmware | >=4.0<4.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0098 is a logic bug vulnerability in the subsystem for Intel(R) CSME and Intel(R) TXE that may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
The severity of CVE-2019-0098 is high, with a CVSS score of 6.8.
CVE-2019-0098 affects versions of Intel Converged Security Management Engine Firmware before 12.0.35 and Intel Trusted Execution Engine Firmware before 4.0.15.
An unauthenticated user can potentially exploit CVE-2019-0098 through physical access to enable escalation of privilege.
You can find more information about CVE-2019-0098 at the following sources: [https://support.f5.com/csp/article/K10522033](https://support.f5.com/csp/article/K10522033) and [https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html](https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html).