#VU29003 Path traversal in Converged Security and Management Engine (CSME) and Intel Trusted Execution Engine Firmware


Published: 2020-06-12

Vulnerability identifier: #VU29003

Vulnerability risk: Low

CVSSv3.1: 2.9 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2020-0539

CWE-ID: CWE-22

Exploitation vector: Local

Exploit availability: No

Vulnerable software:
Converged Security and Management Engine (CSME)
Hardware solutions / Firmware
Intel Trusted Execution Engine Firmware
Hardware solutions / Firmware

Vendor: Intel

Description

The vulnerability allows a local user to perform directory traversal attacks.

The vulnerability exists due to input validation error when processing directory traversal sequences in subsystem for Intel(R) DAL software for Intel(R) CSME. A local user can send a specially crafted HTTP request and cause a denial of service condition on the system.

Note: This vulnerability affects the following versions of Intel CSME and TXE:

CSME:

  • 11.0 through 11.8.76
  • 11.10 through 11.12.76
  • 11.20 through 11.22.76
  • 12.0 through 12.0.63
  • 13.0.31 and 14.0.32
TXE:

  • 3.0 through 3.1.70
  • 4.0 through 4.0.20


Mitigation
Install update from vendor's website.

Vulnerable software versions

Converged Security and Management Engine (CSME): All versions

Intel Trusted Execution Engine Firmware: All versions


External links
http://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00295.html


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability