Uncontrolled resource consumption for some Intel(R) SPS firmware before version SPSE506.01.04.002.0 may allow a privileged user to potentially enable denial of service via network access.
Improper condition check in some Intel(R) SPS firmware before version SPSE306.00.03.300.0 may allow a privileged user to potentially enable denial of service via local access.
Active debug code in some Intel (R) SPS firmware before version SPSE504.04.04.300.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
Missing release of memory after effective lifetime in firmware for Intel(R) SPS before versions SPSE306.00.03.035.0 may allow a privileged user to potentially enable denial of service via local access.
Improper input validation in firmware for Intel(R) SPS before version SPSE304.01.04.700.0 may allow an authenticated user to potentially enable denial of service via local access.
Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPSE304.08.04.330.0 and SPSE304.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access.
Improper input validation in the Intel(R) SPS versions before SPSE504.04.04.023.0, SPSE504.04.03.228.0 or SPSSoC-A05.00.03.098.0 may allow a privileged user to potentially enable denial of service via local access.
Insufficient control flow management in subsystem in Intel(R) SPS versions before SPSE305.01.04.300.0, SPSSoC-A05.00.03.091.0, SPSE504.04.04.023.0, or SPSE504.04.03.263.0 may allow a privileged user to potentially enable escalation of privilege via local access.
Race condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E504.01.04.400 and E305.01.04.200 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Insecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 3.1.80 and 4.0.30, Intel(R) SPS versions before E504.01.04.400, E304.01.04.200, SoC-X04.00.04.200 and SoC-A04.00.04.300 may allow an unauthenticated user to potentially enable escalation of privileges via physical access.
Improper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4.0.30 Intel(R) SPS versions before E305.01.04.200 may allow a privileged user to potentially enable escalation of privilege via local access.
Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPSE504.01.04.380.0, SPSSoC-X04.00.04.128.0, SPSSoC-A04.00.04.211.0, SPSE304.01.04.109.0, SPSE304.08.04.070.0 may allow a privileged user to potentially enable denial of service via local access.
Improper initialization in subsystem for Intel(R) SPS versions before SPSE304.01.04.109.0 and SPSE304.08.04.070.0 may allow an authenticated user to potentially enable escalation of privilege and/or denial of service via local access.
Logic issue in the subsystem for Intel(R) SPS before versions SPSE504.01.04.275.0, SPSSoC-X04.00.04.100.0 and SPSSoC-A04.00.04.191.0 may allow a privileged user to potentially enable denial of service via local access.
Cryptographic timing conditions in the subsystem for Intel(R) PTT before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.0 and 14.0.10; Intel(R) TXE 3.1.70 and 4.0.20; Intel(R) SPS before versions SPSE504.01.04.305.0, SPSSoC-X04.00.04.108.0, SPSSoC-A04.00.04.191.0, SPSE304.01.04.086.0, SPSE304.08.04.047.0 may allow an unauthenticated user to potentially enable information disclosure via network access.
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.
Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPSE305.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Improper data sanitization vulnerability in subsystem in Intel(R) SPS before versions SPSE504.00.04.381.0, SPSE304.01.04.054.0, SPSSoC-A04.00.04.181.0, and SPSSoC-X04.00.04.086.0 may allow a privileged user to potentially enable escalation of privilege via local access.
Insufficient access control vulnerability in subsystem in Intel(R) SPS before version SPSE305.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Insufficient input validation in Intel(R) Server Platform Services HECI subsystem before version SPSE504.00.04.393.0 may allow privileged user to potentially cause a denial of service via local access.
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
Multiple privilege escalations in kernel in Intel Server Platform Services Firmware 4.0 allows unauthorized process to access privileged content via unspecified vector.
Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code.