Vulnerability Details CVE-2019-0098
Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.8%
CVSS Severity
CVSS v3 Score 6.8
CVSS v2 Score 7.2
Products affected by CVE-2019-0098
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.0
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.10
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.11.50
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.11.55
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.11.60
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.20
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.21.51
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.22.0
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.22.60
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.8.50
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.8.55
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:11.8.60
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:12.0
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:12.0.0
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:12.0.10
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:12.0.20
-
cpe:2.3:o:intel:converged_security_management_engine_firmware:12.0.5
-
cpe:2.3:o:intel:trusted_execution_engine_firmware:3.0
-
cpe:2.3:o:intel:trusted_execution_engine_firmware:3.1.50
-
cpe:2.3:o:intel:trusted_execution_engine_firmware:3.1.60
-
cpe:2.3:o:intel:trusted_execution_engine_firmware:4.0
-
cpe:2.3:o:intel:trusted_execution_engine_firmware:4.0.10
-
cpe:2.3:o:intel:trusted_execution_engine_firmware:4.0.5