First published: Wed Dec 18 2019(Updated: )
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=11.0<11.8.70 | |
Intel Converged Security Management Engine Firmware | >=12.0<12.0.45 | |
Intel Converged Security Management Engine Firmware | >=13.0<13.0.10 | |
Intel Trusted Execution Engine Firmware | >=3.0<3.1.70 | |
Intel Trusted Execution Engine Firmware | >=4.0<4.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-0168 is a vulnerability in the subsystem for Intel(R) CSME, Intel(R) TXE, and Intel(R) SPS that may allow a privileged user to enable information disclosure via local access.
The severity of CVE-2019-0168 is medium, with a CVSS score of 4.4.
CVE-2019-0168 affects Intel Converged Security Management Engine Firmware versions 11.0 to 11.8.70, 12.0 to 12.0.45, and 13.0 to 13.0.10, potentially allowing information disclosure via local access.
CVE-2019-0168 affects Intel Trusted Execution Engine Firmware versions 3.0 to 3.1.70 and 4.0 to 4.0.20.
To fix CVE-2019-0168, update to the latest versions of Intel Converged Security Management Engine Firmware and Intel Trusted Execution Engine Firmware.