CVE-2019-0153

CRITICAL

Intel Converged Security Management Engine Firmware < 12.0.35 - Unauthenticated Buffer Overflow via Network Access

Title source: llm
STIX 2.1

Description

Buffer overflow in subsystem in Intel(R) CSME 12.0.0 through 12.0.34 may allow an unauthenticated user to potentially enable escalation of privilege via network access.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_confirm
https://support.f5.com/csp/article/K71265658

Scores

CVSS v3 9.8
EPSS 0.0057
EPSS Percentile 68.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
intel/converged_security_management_engine_firmware < 12.0.35
Published May 17, 2019
Tracked Since Feb 18, 2026