CVE-2020-24516: Intel Converged Security And Manageability Engine
Medium severity, CVSS 6.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Modification of assumed-immutable data in subsystem in Intel(R) CSME versions before 13.0.47, 13.30.17, 14.1.53, 14.5.32, 15.0.22 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Affected products
- Intel Converged Security And Manageability Engine: before 13.0.47 (fixed in 13.0.47); before 13.30.17 (fixed in 13.30.17); before 14.1.53 (fixed in 14.1.53); before 14.5.32 (fixed in 14.5.32); before 15.0.22 (fixed in 15.0.22)
Published 2021-06-09. Last modified 2026-06-17.