CVE-2019-0168: Input Validation
Insufficient input validation in the subsystem for Intel(R) CSME before versions 11.8.70, 12.0.45 and 13.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-0168?
CVE-2019-0168 is a vulnerability in the subsystem for Intel(R) CSME, Intel(R) TXE, and Intel(R) SPS that may allow a privileged user to enable information disclosure via local access.
What is the severity of CVE-2019-0168?
The severity of CVE-2019-0168 is medium, with a CVSS score of 4.4.
How does CVE-2019-0168 affect Intel Converged Security Management Engine Firmware?
CVE-2019-0168 affects Intel Converged Security Management Engine Firmware versions 11.0 to 11.8.70, 12.0 to 12.0.45, and 13.0 to 13.0.10, potentially allowing information disclosure via local access.
What are the affected versions of Intel Trusted Execution Engine Firmware?
CVE-2019-0168 affects Intel Trusted Execution Engine Firmware versions 3.0 to 3.1.70 and 4.0 to 4.0.20.
How can I fix CVE-2019-0168?
To fix CVE-2019-0168, update to the latest versions of Intel Converged Security Management Engine Firmware and Intel Trusted Execution Engine Firmware.