← Vulnerability feed

Vulnerability record · CVE-2020-24506 · published 9 June 2021

CVE-2020-24506: Intel converged security and manageability engine out-of-bounds read vulnerability

Intel · Converged Security And Manageability Engine

Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access.

4.4 CVSS 3.1 Medium EPSS 0.28% · top 81.0% CWE-125 · Out-of-bounds read
4.4CVSS 3.1 base score, v2 2.1
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Out of bound read in a subsystem in the Intel(R) CSME versions before 12.0.81, 13.0.47, 13.30.17, 14.1.53 and 14.5.32 may allow a privileged user to potentially enable information disclosure via local access.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-24506 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.2CVE-2021-41838Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access …EPSS 0.30%8.2CVE-2021-41837Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM …EPSS 0.28%8.2CVE-2021-42554Insydeh2o out-of-bounds write vulnerabilityAn issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 befor…EPSS 0.33%8.2CVE-2021-33627Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.…EPSS 0.33%7.8CVE-2021-33626Insydeh2o inclusion from untrusted sphere vulnerabilityA vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocat…EPSS 0.31%7.8CVE-2020-0590Intel xeon bronze 3206r firmware improper input validation vulnerabilityImproper input validation in BIOS firmware for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege…EPSS 0.42%7.8CVE-2020-12297Intel converged security and manageability engine vulnerabilityImproper access control in Installer for Intel(R) CSME Driver for Windows versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14…EPSS 0.45%7.8CVE-2020-12303Intel converged security and manageability engine use after free vulnerabilityUse after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2020-24506), CISA KEV, FIRST EPSS (scores of 2026-10-02). This page is refreshed as NVD updates the record.