CVE-2023-40067: Intel Converged Security Management Engine Firmware
Medium severity, CVSS 5.7. EPSS: 0.2% chance of exploitation in the next 30 days.
Unchecked return value in firmware for some Intel(R) CSME may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
Affected products
- Intel Converged Security Management Engine Firmware: before 15.0.49 (fixed in 15.0.49); before 15.40.34 (fixed in 15.40.34); before 16.1.32 (fixed in 16.1.32)
Published 2024-08-14. Last modified 2026-06-17.