Known vulnerabilities in Converged Security and Management Engine (CSME)

Vendor: Intel
Software CPE: cpe:2.3:h:intel:csme:*:*:*:*:*:*:*:*
Total vulnerabilities: 30
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.2

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Converged Security and Management Engine (CSME) Converged Security and Management Engine (CSME) is affected by 30 known vulnerabilities: 2 high, 4 medium, 24 low Critical High Medium Low

Vulnerabilities (30)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU104063 - Improper input validation
CVE-2024-38307
CWE-20 Medium
No
No
- 19.02.2025 SB2025022014
SB2025051632
SB2025052076
#VU96076 - Improper input validation
CVE-2023-34424
CWE-20 Low
No
No
- 16.08.2024 SB2024081629
SB20250520128
#VU96074 - Integer overflow
CVE-2024-21844
CWE-190 Low
No
No
- 16.08.2024 SB2024081629
SB20250520128
#VU96073 - Improper Initialization
CVE-2023-48361
CWE-665 Low
No
No
- 16.08.2024 SB2024081629
SB20250520128
#VU96072 - Unchecked Return Value
CVE-2023-40067
CWE-252 Low
No
No
- 16.08.2024 SB2024081629
SB20250520128
#VU79563 - Improper input validation
CVE-2022-38102
CWE-20 Low
No
No
15.0.45, 16.1.27 15.08.2023 SB2023081549
SB2023082235
SB20230808148
#VU79562 - Improper input validation
CVE-2022-36392
CWE-20 Medium
No
No
11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45, 16.1.27 15.08.2023 SB2023081549
SB2023082235
SB2023082236
and 1 more
#VU69317 - Improper input validation
CVE-2022-29515
CWE-20 Low
No
No
11.8.93, 11.12.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 15.11.2022 SB2022111522
SB2023031313
SB2023081531
#VU69316 - Improper input validation
CVE-2022-29466
CWE-20 Low
No
No
11.8.93, 11.12.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 15.11.2022 SB2022111522
SB2023010502
SB2023031313
and 1 more
#VU69315 - NULL Pointer Dereference
CVE-2022-27497
CWE-476 High
No
No
11.8.93, 11.12.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 15.11.2022 SB2022111522
SB2023022344
SB2023031313
#VU69314 - Improper Authentication
CVE-2021-33159
CWE-287 Low
No
No
11.8.93, 11.12.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 15.11.2022 SB2022111522
SB2023022344
SB2023031313
and 1 more
#VU69313 - Improper Authentication
CVE-2022-29893
CWE-287 Medium
No
No
11.8.93, 11.12.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 15.11.2022 SB2022111522
SB2023022344
SB2023031313
#VU69312 - Improper Authentication
CVE-2022-26845
CWE-287 High
No
No
11.8.93, 11.12.93, 11.22.93, 12.0.92, 14.1.67, 15.0.42, 16.1.25 15.11.2022 SB2022111522
SB2023022344
SB2023031313
#VU54199 - Out-of-bounds read
CVE-2020-24506
CWE-125 Low
No
No
12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32 17.06.2021 SB2021061712
SB2021081109
SB2022111726
and 1 more
#VU54198 - Memory corruption
CVE-2020-8703
CWE-119 Low
No
No
11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22 17.06.2021 SB2021061712
SB2021081109
SB2022111726
#VU54197 - Permissions, Privileges, and Access Controls
CVE-2020-24516
CWE-264 Low
No
No
13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22 17.06.2021 SB2021061712
#VU54196 - Exposure of sensitive information to an unauthorized actor
CVE-2020-24507
CWE-200 Low
No
No
11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 13.50.11, 14.1.53, 14.5.32, 15.0.22 17.06.2021 SB2021061712
SB2021081109
SB2022111726
and 1 more
#VU48680 - Improper Initialization
CVE-2020-8744
CWE-665 Low
No
No
12.0.70, 13.0.40, 13.30.10, 14.0.45, 14.5.25 12.11.2020 SB2020112614
SB2021051312
#VU48681 - Improper Initialization
CVE-2020-8705
CWE-665 Low
No
No
11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45, 14.5.25 12.11.2020 SB2020112616
#VU48682 - Use After Free
CVE-2020-12303
CWE-416 Low
No
No
11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45, 14.5.25 12.11.2020 SB2020112614


Showing elements 1 - 20 out of 30