PT-2024-7103 · Intel · Intel Csme

Alexander Kantor

+1

·

Published

2024-08-13

·

Updated

2024-08-14

·

CVE-2023-40067

CVSS v3.1

5.7

Medium

VectorAV:P/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Intel(R) CSME (affected versions not specified)
Description The issue is related to an unchecked return value in the firmware of some Intel Converged Security and Manageability Engine (CSME) subsystems. This may allow an unauthenticated user with physical access to potentially enable escalation of privilege. The vulnerability is associated with incorrect checking of the return value of a method or function, which could lead to privilege escalation or denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Unchecked Return Value

Weakness Enumeration

Related Identifiers

BDU:2024-08370
CVE-2023-40067

Affected Products

Intel Csme