CVE-2019-14598: Intel Converged Security Management Engine Firmware
Medium severity, CVSS 6.7. EPSS: 0.5% chance of exploitation in the next 30 days.
Improper Authentication in subsystem in Intel(R) CSME versions 12.0 through 12.0.48 (IOT only: 12.0.56), versions 13.0 through 13.0.20, versions 14.0 through 14.0.10 may allow a privileged user to potentially enable escalation of privilege, denial of service or information disclosure via local access.
Affected products
- Intel Converged Security Management Engine Firmware: from 12.0, before 12.0.48 (fixed in 12.0.48); from 12.0, before 12.0.56 (fixed in 12.0.56); from 13.0, before 13.0.20 (fixed in 13.0.20); from 14.0, before 14.0.10 (fixed in 14.0.10)
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
Published 2020-02-13. Last modified 2026-06-17.