CVE-2023-28389: Intel Converged Security And Manageability Engine

Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.

Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected products

  • Intel Converged Security And Manageability Engine: before 2328.5.5.0 (fixed in 2328.5.5.0)

Published 2024-03-14. Last modified 2026-06-17.