CVE-2020-24506: Medium severity intel converged security and manageability engine vulnerability
Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-24506?
The severity of CVE-2020-24506 is considered high due to potential information disclosure through out-of-bounds reads.
How do I fix CVE-2020-24506?
To fix CVE-2020-24506, users should update to Intel Converged Security and Manageability Engine versions 12.0.81, 13.0.47, 13.30.17, 14.1.53, or 14.5.32.
Which systems are affected by CVE-2020-24506?
CVE-2020-24506 affects various Intel systems running vulnerable versions of the Converged Security and Manageability Engine.
Is local access required to exploit CVE-2020-24506?
Yes, exploitation of CVE-2020-24506 requires local access to the vulnerable system.
What is the impact of CVE-2020-24506?
The impact of CVE-2020-24506 is potential information disclosure, which could expose sensitive data to privileged users.