CVE-2019-11104

HIGH WAF: Medium
CVSS 7.8 Published: 2019-12-18
CWE-20

Insufficient input validation in MEInfo software for Intel(R) CSME before versions 11.8.70, 11.11.70, 11.22.70, 12.0.45, 13.0.10 and 14.0.10; Intel(R) TXE before versions 3.1.70 and 4.0.20 may allow an authenticated user to potentially enable escalation of privilege via local access.

WAF Coverage Analysis

Improper Input Validation Medium WAF Coverage

OWASP: A03:2021 Injection

920xxx - Protocol Enforcement 941xxx - XSS / XXE 942xxx - SQL Injection

Affected Software

VendorProductVersion
intelconverged_security_management_engine_firmware11.0 - 11.8.70
intelconverged_security_management_engine_firmware11.10 - 11.11.70
intelconverged_security_management_engine_firmware11.20 - 11.22.70
intelconverged_security_management_engine_firmware12.0 - 12.0.45
intelconverged_security_management_engine_firmware13.0 - 13.0.10
intelconverged_security_management_engine_firmware14.0.0 - 14.0.10
inteltrusted_execution_engine_firmware3.0 - 3.1.70
inteltrusted_execution_engine_firmware4.0 - 4.0.20

References

Back to CVE Database