CVE-2020-0545
MEDIUMIntel Converged Security Management Engine Firmware < 11.8.77 - Denial of Service via Integer Overflow
Title source: llmDescription
Integer overflow in subsystem for Intel(R) CSME versions before 11.8.77, 11.12.77, 11.22.77 and Intel(R) TXE versions before 3.1.75, 4.0.25 and Intel(R) Server Platform Services (SPS) versions before SPS_E5_04.01.04.380.0, SPS_SoC-X_04.00.04.128.0, SPS_SoC-A_04.00.04.211.0, SPS_E3_04.01.04.109.0, SPS_E3_04.08.04.070.0 may allow a privileged user to potentially enable denial of service via local access.
References (5)
Core 5
Core References
Vendor Advisory x_refsource_confirm
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200611-0006/
Vendor Advisory x_refsource_confirm
https://kc.mcafee.com/corporate/index?page=content&id=SB10321
Vendor Advisory x_refsource_confirm
https://cert-portal.siemens.com/productcert/pdf/ssa-631949.pdf
Various Sources x_refsource_misc
https://support.lenovo.com/de/en/product_security/len-30041
Scores
CVSS v3
4.4
EPSS
0.0010
EPSS Percentile
27.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-190
Status
published
Products (3)
intel/converged_security_management_engine_firmware
11.0 - 11.8.77
intel/server_platform_services
sps_e3_04.00.00.000.0 - sps_e3_04.01.04.109.0
intel/trusted_execution_engine
3.0 - 3.1.75
Published
Jun 15, 2020
Tracked Since
Feb 18, 2026