« Volver al listado

CVE-2019-0093

Estado: ModificadaMedia (4.4)—

Insufficient data sanitization vulnerability in HECI subsystem for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow a privileged user to potentially enable information disclosure via local access.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-0093",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 4.4,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Intel(R) Converged Security & Management Engine (CSME), Intel(R) Server Platform Services (SPS)",
          "versions": [
            {
              "status": "affected",
              "version": "Versions before 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) SPS before version SPS_E3_05.00.04.027.0."
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-05-17T16:29:01.140",
  "references": [
    {
      "url": "https://support.f5.com/csp/article/K13710800",
      "source": "secure@intel.com"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://support.f5.com/csp/article/K13710800",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00213.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Insufficient data sanitization vulnerability in HECI subsystem for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow a privileged user to potentially enable information disclosure via local access."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad por inadecuado saneamiento de datos en el subsistema HECI para Intel (R) CSME anterior a las versiones 11.8.65, 11.11.65, 11.22.65, 12.0.35 y Intel (R) SPS anterior a la versión SPS_E3_05.00.04.027.0 puede permitir que un usuario con privilegios pueda potencialmente habilitar la divulgación de información a través del acceso local."
    }
  ],
  "lastModified": "2026-06-17T02:07:41.307",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:intel:converged_security_and_management_engine:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB2C110D-88CC-47EF-87F7-5925553470D7",
              "versionEndExcluding": "11.8.65",
              "versionStartIncluding": "11.8.0"
            },
            {
              "criteria": "cpe:2.3:a:intel:converged_security_and_management_engine:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E57A76A-714A-42C6-A364-394FCE12F636",
              "versionEndExcluding": "11.11.65",
              "versionStartIncluding": "11.11.0"
            },
            {
              "criteria": "cpe:2.3:a:intel:converged_security_and_management_engine:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1104A893-6E27-4908-8BA1-3A1EF334BD8B",
              "versionEndExcluding": "11.22.65",
              "versionStartIncluding": "11.22.0"
            },
            {
              "criteria": "cpe:2.3:a:intel:converged_security_and_management_engine:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2724FD1-2375-40A9-BAEE-0D7AAF91F329",
              "versionEndExcluding": "12.0.35",
              "versionStartIncluding": "12.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@intel.com"
}