Vulnerability record · CVE-2019-14598 · published 13 February 2020
CVE-2019-14598: Intel converged security management engine firmware improper authentication vulnerability
Intel · Converged Security Management Engine Firmware
Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
Description
Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://security.netapp.com/advisory/ntap-20200221-0005/ | Third Party Advisory |
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00307.html | Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20200221-0005/ | Third Party Advisory |
| https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00307.html | Vendor Advisory |
Track CVE-2019-14598 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-14598), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.