CVE-2019-0090

HIGH

Intel CSME <11.x-12.0.35 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://support.f5.com/csp/article/K59145983

Scores

CVSS v3 7.1
EPSS 0.0038
EPSS Percentile 59.8%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

Status published
Products (2)
intel/converged_security_and_management_engine < 12.0.35
intel/server_platform_services < sps_e3_05.00.04.027.0
Published May 17, 2019
Tracked Since Feb 18, 2026