CVE-2019-0093: Intel Converged Security And Management Engine

Medium severity, CVSS 4.4. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient data sanitization vulnerability in HECI subsystem for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) SPS before version SPS_E3_05.00.04.027.0 may allow a privileged user to potentially enable information disclosure via local access.

Affected products

  • Intel Converged Security And Management Engine: from 11.8.0, before 11.8.65 (fixed in 11.8.65); from 11.11.0, before 11.11.65 (fixed in 11.11.65); from 11.22.0, before 11.22.65 (fixed in 11.22.65); from 12.0, before 12.0.35 (fixed in 12.0.35)

Published 2019-05-17. Last modified 2026-06-17.