First published: Wed Jun 09 2021(Updated: )
Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security and Manageability Engine | <12.0.81 | |
Intel B360 | ||
Intel B365 | ||
Intel C242 Firmware | ||
Intel C246 Firmware | ||
Intel Celeron 4205U | ||
Intel Celeron 4305U Firmware | ||
Intel Celeron 4305UE Firmware | ||
Intel Core i3-8100H Firmware | ||
Intel Core i3-8100B | ||
Intel Core i3-8100H Firmware | ||
Intel Core i3-8100T Firmware | ||
Intel Core i3-8109U Firmware | ||
Intel Core i3-8121U Firmware | ||
Intel Core i3-8130U Firmware | ||
Intel Core i3-8140U Firmware | ||
Intel Core i3-8145u firmware | ||
Intel Core i3-8145UE Firmware | ||
Intel Core i3 8300 Firmware | ||
Intel Core i3-8300T Firmware | ||
Intel Core i3-8350K | ||
Intel Core i5-8200Y | ||
Intel Core i5-8210Y Firmware | ||
Intel Core i5-8250U Firmware | ||
Intel Core i5-8257U Firmware | ||
Intel Core i5-8259U Firmware | ||
Intel Core i5-8260U | ||
Intel Core i5-8265U Firmware | ||
Intel Core i5-8269U | ||
Intel Core i5-8279U Firmware | ||
Intel Core i5-8300H firmware | ||
Intel Core i5-8305G Firmware | ||
Intel Core i5-8310Y Firmware | ||
Intel Core i5-8350U firmware | ||
Intel Core i5-8365UE Firmware | ||
Intel Core i5-8365UE Firmware | ||
Intel Core i5-8400 | ||
Intel Core i5-8400B | ||
Intel Core i5-8400H Firmware | ||
Intel Core i5-8400T firmware | ||
Intel Core i5-8500B Firmware | ||
Intel Core i5-8500 | ||
Intel Core i5-8500T | ||
Intel Core i5-8600 Firmware | ||
Intel Core i5-8600K Firmware | ||
Intel Core i5-8600T Firmware | ||
Intel Core i7-8086K Firmware | ||
Intel Core i7-8500Y Firmware | ||
Intel Core i7-8550U firmware | ||
Intel Core i7-8557U Firmware for Windows | ||
Intel Core i7-8559U Firmware for Windows | ||
Intel Core i7-8565U firmware | ||
Intel Core i7-8569U Firmware | ||
Intel Core i7-8650U Firmware | ||
Intel Core i7-8665U firmware | ||
Intel Core i7-8665UE Firmware | ||
Intel Core i7-8700b firmware | ||
Intel Core i7-8700b firmware | ||
Intel Core i7-8700K | ||
Intel Core i7-8700T firmware | ||
Intel Core i7-8705G firmware | ||
Intel Core i7-8706g firmware | ||
Intel Core i7-8709G Firmware | ||
Intel Core i7-8750H | ||
Intel Core i7-8809G Firmware | ||
Intel Core i7-8850H firmware | ||
Intel Core i9-8950HK Firmware | ||
Intel H310 | ||
Intel H370 | ||
Intel CM246 | ||
Intel Pentium Gold 4410Y Firmware | ||
Intel Pentium 4415U | ||
Intel Core 4415Y | ||
Intel Pentium Gold 4417U Firmware | ||
Intel Pentium Gold 4425Y Firmware | ||
Intel Pentium Gold 5405U Firmware | ||
Intel Pentium Gold 6405U Firmware | ||
Intel Pentium Gold 6500Y | ||
Intel Pentium Gold 7505 Firmware | ||
Intel Pentium Gold G5400 Firmware | ||
Intel Pentium Gold G5400T | ||
Intel Pentium Gold G5420 Firmware | ||
Intel Pentium G5420T | ||
Intel Pentium Gold G5500 Firmware | ||
Intel Pentium G5500 | ||
Intel Pentium G5600 | ||
Intel Pentium Gold G5600T | ||
Intel Pentium Gold G5620 Firmware | ||
Intel Pentium Gold G6400 Firmware | ||
Intel Pentium Gold G6400E Firmware | ||
Intel Pentium Gold G6400 Firmware | ||
Intel Pentium Gold G6400 Firmware | ||
Intel Pentium Gold G6405 Firmware | ||
Intel Pentium Gold G6405T Firmware | ||
Intel Pentium Gold G6500 Firmware | ||
Intel Pentium Gold G6500T Firmware | ||
Intel Pentium Gold G6505 Firmware | ||
Intel Pentium Gold G6505 Firmware | ||
Intel Pentium Gold G6600 Firmware | ||
Intel Pentium Gold G6605 | ||
Intel Q370 | ||
Intel Xeon W-10855M Firmware | ||
Intel Xeon W-10885M Firmware | ||
Intel Xeon W-11855M Firmware | ||
Intel Xeon W-11955M Firmware | ||
Intel Xeon W-1250 Firmware | ||
Intel Xeon W-1250E Firmware | ||
Intel Xeon W-1250P Firmware | ||
Intel Xeon W-1250TE Firmware | ||
Intel Xeon W-1270 Firmware | ||
Intel Xeon W-1270E Firmware | ||
Intel Xeon W-1270P Firmware | ||
Intel Xeon W-1270TE Firmware | ||
Intel Xeon W-1290 Firmware | ||
Intel Xeon W-1290E Firmware | ||
Intel Xeon W-1290P Firmware | ||
Intel Xeon W-1290T Firmware | ||
Intel Xeon W-1290TE Firmware | ||
Intel Z370 | ||
Intel Z390 | ||
Intel Converged Security and Manageability Engine | <13.0.47 | |
Intel Core i3-1000G1 Firmware | ||
Intel Core i3-1000G4 Firmware | ||
Intel Core i3-1000NG4 Firmware | ||
Intel Core i3-1005G1 firmware | ||
Intel Core i3-10100F Firmware | ||
Intel Core i3-10100E Firmware | ||
Intel Core i3-10100F Firmware | ||
Intel Core i3-10100T Firmware | ||
Intel Core i3-10100TE Firmware | ||
Intel Core i3-10100Y Firmware | ||
Intel Core i3-10105F | ||
Intel Core i3-10105F Firmware | ||
Intel Core i3-10105T Firmware | ||
Intel Core i3-10110u | ||
Intel Core i3-10110Y | ||
Intel Core i3-10300 firmware | ||
Intel Core i3-10300T Firmware | ||
Intel Core i3-10305 | ||
Intel Core i3-10305T | ||
Intel Core i3-10320 Firmware | ||
Intel Core i3-10325 | ||
Intel Core i5-10200H Firmware | ||
Intel Core i5-10210U firmware | ||
Intel Core i5-10210Y Firmware | ||
Intel Core i5-10300H Firmware | ||
Intel Core i5-1030G4 Firmware | ||
Intel Core i5-1030NG7 Firmware | ||
Intel Core i5-1030NG7 Firmware | ||
Intel Core i5-10310U Firmware | ||
Intel Core i5-10310Y Firmware | ||
Intel Core i5-1035G1 | ||
Intel Core i5-1035G4 | ||
Intel Core i5-1035G7 Firmware | ||
Intel Core i5-1038NG7 | ||
Intel Core i5-10400F | ||
Intel Core i5-10400 | ||
Intel Core i5-10400H firmware | ||
Intel Core i5-10400T Firmware | ||
Intel Core i5-10500E Firmware | ||
Intel Core i5-10500E Firmware | ||
Intel Core i5-10500H Firmware | ||
Intel Core i5-10500T Firmware | ||
Intel Core i5-10500TE Firmware | ||
Intel Core i5-10505 Firmware | ||
Intel Core i5-10600 Firmware | ||
Intel Core i5-10600K Firmware | ||
Intel Core i5-10600K Firmware | ||
Intel Core i5-10600T Firmware | ||
Intel Core i7-10510U Firmware | ||
Intel Core i7-10510Y Firmware | ||
Intel Core i7-1060G7 Firmware | ||
Intel Core i7-1060NG7 Firmware | ||
Intel Core i7-10610U Firmware | ||
Intel Core i7-1065G7 Firmware | ||
Intel Core i7-1068NG7 Firmware | ||
Intel Core i7-10700 | ||
Intel Core i7-10700E firmware | ||
Intel Core i7-10700F Firmware | ||
Intel Core i7-10700K Firmware | ||
Intel Core i7-10700K Firmware | ||
Intel Core i7-10700T Firmware | ||
Intel Core i7-10700TE Firmware | ||
Intel Core i7-10710U Firmware | ||
Intel Core i7-10750H Firmware | ||
Intel Core i7-10810U Firmware | ||
Intel Core i7-10850H Firmware | ||
Intel Core i7-10870H | ||
Intel Core i7-10875H Firmware | ||
Intel Core i9-10850K Firmware | ||
Intel Core i9-10885H Firmware | ||
Intel Core i9-10900E firmware | ||
Intel Core i9-10900E firmware | ||
Intel Core i9-10900F Firmware | ||
Intel Core i9-10900K Firmware | ||
Intel Core i9-10900K | ||
Intel Core i9-10900T Firmware | ||
Intel Core i9-10900TE Firmware | ||
Intel Core i9-10910 Firmware | ||
Intel Core i9-10980HK | ||
Intel Converged Security and Manageability Engine | <13.30.17 | |
Intel Core i3-L13G4 Firmware | ||
Intel Core i5-L16G7 Firmware | ||
Intel Converged Security and Manageability Engine | <14.1.53 | |
Intel B460 | ||
Intel H410 | ||
Intel H420E | ||
Intel H470 | ||
Intel Q470 | ||
Intel Q470E | ||
Intel W480 | ||
Intel W480E | ||
Intel Z490 | ||
Intel Converged Security and Manageability Engine | <14.5.32 | |
Siemens Simatic Field PG M6 Firmware | ||
Siemens Simatic Field PG M6 Firmware | ||
Siemens Simatic IPC627E Firmware | <25.02.10 | |
Siemens Simatic IPC627E Firmware | ||
Siemens Simatic IPC647E Firmware | <25.02.10 | |
Siemens Simatic IPC647E Firmware | ||
Siemens Simatic IPC677E Firmware | <25.02.10 | |
Siemens Simatic IPC677E Firmware | ||
Siemens Simatic IPC847E Firmware | <25.02.10 | |
Siemens Simatic IPC847E Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-24506 is considered high due to potential information disclosure through out-of-bounds reads.
To fix CVE-2020-24506, users should update to Intel Converged Security and Manageability Engine versions 12.0.81, 13.0.47, 13.30.17, 14.1.53, or 14.5.32.
CVE-2020-24506 affects various Intel systems running vulnerable versions of the Converged Security and Manageability Engine.
Yes, exploitation of CVE-2020-24506 requires local access to the vulnerable system.
The impact of CVE-2020-24506 is potential information disclosure, which could expose sensitive data to privileged users.