← Vulnerability feed

Vulnerability record · CVE-2020-24507 · published 9 June 2021

CVE-2020-24507: Intel converged security and manageability engine vulnerability

Intel · Converged Security And Manageability Engine

Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access.

4.4 CVSS 3.1 Medium EPSS 0.28% · top 81.0% CWE-665 · CWE-665
4.4CVSS 3.1 base score, v2 2.1
0.28%EPSS exploitation probability, 30 days
NoNot in CISA KEV
13Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

Improper initialization in a subsystem in the Intel(R) CSME versions before 11.8.86, 11.12.86, 11.22.86, 12.0.81, 13.0.47, 13.30.17, 14.1.53, 14.5.32, 13.50.11 and 15.0.22 may allow a privileged user to potentially enable information disclosure via local access.

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N

Affected products

13 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-24507 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2017-5689Intel AMT, ISM and SBT improper privilege management allows privilege escalationIntel manageability SKUs (AMT, ISM, SBT) contain an improper privilege management flaw. An unprivileged network attacker can gain system privileges o…KEVEPSS 92%analysed8.2CVE-2021-41837Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM …EPSS 0.28%8.2CVE-2021-42554Insydeh2o out-of-bounds write vulnerabilityAn issue was discovered in Insyde InsydeH2O with Kernel 5.0 before 05.08.42, Kernel 5.1 before 05.16.42, Kernel 5.2 before 05.26.42, Kernel 5.3 befor…EPSS 0.33%8.2CVE-2021-41838Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in SdHostDriver in the kernel 5.0 through 5.5 in Insyde InsydeH2O. There is an SMM callout that allows an attacker to access …EPSS 0.30%8.2CVE-2021-33627Insydeh2o memory buffer overflow vulnerabilityAn issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.09.11, 5.1 before 05.17.11, 5.2 before 05.27.11, 5.3 before 05.36.11, 5.4 before 05.…EPSS 0.33%7.8CVE-2021-33626Insydeh2o inclusion from untrusted sphere vulnerabilityA vulnerability exists in SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocat…EPSS 0.31%7.8CVE-2020-12297Intel converged security and manageability engine vulnerabilityImproper access control in Installer for Intel(R) CSME Driver for Windows versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14…EPSS 0.45%7.8CVE-2020-12303Intel converged security and manageability engine use after free vulnerabilityUse after free in DAL subsystem for Intel(R) CSME versions before 11.8.80, 11.12.80, 11.22.80, 12.0.70, 13.0.40, 13.30.10, 14.0.45 and 14.5.25, Intel…EPSS 0.37%

Source: NIST National Vulnerability Database (record CVE-2020-24507), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.