CVE-2019-11110: Medium severity intel converged security and management engine vulnerability
Authentication bypass in the subsystem for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow a privileged user to potentially enable escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11110?
CVE-2019-11110 is a vulnerability that allows a privileged user to potentially enable escalation of privilege via local access in Intel Converged Security Management Engine Firmware and Intel Trusted Execution Engine Firmware.
What is the severity of CVE-2019-11110?
CVE-2019-11110 has a severity score of 6.7, which is considered medium.
Which versions of Intel Converged Security Management Engine Firmware are affected by CVE-2019-11110?
Intel Converged Security Management Engine Firmware versions 11.0 to 11.8.70, 11.10 to 11.11.70, and 11.20 to 11.22.70 are affected by CVE-2019-11110.
Which versions of Intel Trusted Execution Engine Firmware are affected by CVE-2019-11110?
Intel Trusted Execution Engine Firmware versions 3.0 to 3.1.70 and 4.0 to 4.0.20 are affected by CVE-2019-11110.
How can I fix CVE-2019-11110?
To fix CVE-2019-11110, it is recommended to update to the latest versions of Intel Converged Security Management Engine Firmware (versions above 11.8.70, 11.11.70, and 11.22.70) and Intel Trusted Execution Engine Firmware (versions above 3.1.70 and 4.0.20). Please refer to the official Intel Security Advisory for more information.