← Vulnerability feed

Vulnerability record · CVE-2019-0090 · published 17 May 2019

CVE-2019-0090: Intel converged security and management engine vulnerability

Intel · Converged Security And Management Engine

Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

7.1 CVSS 3.1 High EPSS 0.36% · top 72.8%
7.1CVSS 3.1 base score, v2 4.4
0.36%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Insufficient access control vulnerability in subsystem for Intel(R) CSME before versions 11.x, 12.0.35 Intel(R) TXE 3.x, 4.x, Intel(R) Server Platform Services 3.x, 4.x, Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.

CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-0090 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2022-36348Intel server platform services vulnerabilityActive debug code in some Intel (R) SPS firmware before version SPS_E5_04.04.04.300.0 may allow an authenticated user to potentially enable escalatio…EPSS 0.20%7.8CVE-2020-8744Intel converged security and management engine vulnerabilityImproper initialization in subsystem for Intel(R) CSME versions before12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel(R) TXE versions before 4…EPSS 0.36%7.8CVE-2020-0586Intel server platform services vulnerabilityImproper initialization in subsystem for Intel(R) SPS versions before SPS_E3_04.01.04.109.0 and SPS_E3_04.08.04.070.0 may allow an authenticated user…EPSS 0.37%7.8CVE-2019-0091Intel converged security and management engine code injection vulnerabilityCode injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may …EPSS 0.52%6.8CVE-2020-8705Intel converged security and manageability engine insecure default initialization vulnerabilityInsecure default initialization of resource in Intel(R) Boot Guard in Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13…EPSS 0.50%6.7CVE-2020-24509Intel server platform services vulnerabilityInsufficient control flow management in subsystem in Intel(R) SPS versions before SPS_E3_05.01.04.300.0, SPS_SoC-A_05.00.03.091.0, SPS_E5_04.04.04.02…EPSS 0.25%6.7CVE-2019-0089Intel server platform services vulnerabilityImproper data sanitization vulnerability in subsystem in Intel(R) SPS before versions SPS_E5_04.00.04.381.0, SPS_E3_04.01.04.054.0, SPS_SoC-A_04.00.0…EPSS 0.38%6.4CVE-2020-8755Intel converged security and management engine race condition vulnerabilityRace condition in subsystem for Intel(R) CSME versions before 12.0.70 and 14.0.45, Intel(R) SPS versions before E5_04.01.04.400 and E3_05.01.04.200 m…EPSS 0.28%

Source: NIST National Vulnerability Database (record CVE-2019-0090), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.