CVE-2018-3659: Intel Converged Security Management Engine Firmware

Medium severity, CVSS 6.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.

Affected products

  • Intel Converged Security Management Engine Firmware: before 12.0.5 (fixed in 12.0.5)
  • Intel Trusted Execution Engine Firmware: before 4.0 (fixed in 4.0)

Published 2018-09-12. Last modified 2026-06-17.