Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted
Novice
150 Views

NUC6CAYH vulnerable according CSME Version Detection Tool

Intel® Converged Security and Management Engine Version Detection Tool Version: 4.0.1.0 (3.1.0.0 as well BTW) reports the NUC6CAYH as being vulnerable on the Trusted Execution Engine being at version 3.1.70.2334

Latest bios update is from end 2019,  is the TXE going to be patched on this NUC model?

Tags (1)
0 Kudos
11 Replies
Highlighted
Moderator
125 Views

Hello RvdH,

Thank you for posting on the Intel® communities.  

The BIOS version 0066 contains security fixes. This BIOs version is dated for 12/17/2019.

I would strongly recommend the update of the latest BIOS version. You can find it here.


After the update of the BIOS please run the utility again. In case the vulnerability message still showing after the update I would appreciate if you could attach a picture of the message to the thread.


Please reply at your earliest convenience to check results.


Esteban D.

Intel Technical Support Technician  


0 Kudos
Highlighted
Novice
119 Views

@Esteban_D_Intel 

Sorry, i think you misunderstood me, the unit is already running the latest bios 0066I also have a NUC6CAYS model that reports the same issue,  this unit is also running the latest bios 0066

Screenshots attached, CSME Version Detection Tool 3.1.0.0 and CSME Version Detection Tool 4.0.1.0

0 Kudos
Highlighted
Novice
114 Views

SSU report 

BaseBoard Manufacturer	Intel Corporation	
BIOS Mode	Legacy	
BIOS Version/Date	Intel Corp. AYAPLCEL.86A.0066.2020.0107.1027 , 07-01-2020 12:00	
CD or DVD	Not Available	
Embedded Controller Version	22.0	
Platform Role	Desktop	
Processor	Intel(R) Celeron(R) CPU J3455 @ 1.50GHz , GenuineIntel	
Secure Boot State	On	
SMBIOS Version	3.0	
Sound Card	Not Available	
System Manufacturer	Intel Corporation	
System Model	NUC6CAYH	
System SKU	Not Available	
System Type	x64-based PC	
0 Kudos
Highlighted
Super User Retired Employee
105 Views

@RvdH,

The SSU tool has the capability to save the report as a text file. Please produce this file and attach to a response post.

...S 

0 Kudos
Highlighted
Moderator
95 Views

Hello RvdH,

Thank you so much for your response and clarification.


I would appreciate if you could attach the full SSU report following the steps below:

    

Intel® System Support Utility (Intel® SSU) Download link 

  

1. Open the application and click on "Scan" to see the system and device information. 

2. By default, Intel® SSU will take you to the "Summary View".   

3. Click on the menu where it says "Summary" to change to "Detailed View".   

4. To save your scan, click on "Next", then "Save".   

 

 

Esteban D.

Intel Technical Support Technician  


0 Kudos
Highlighted
Novice
90 Views

Why?  On the SSU excerpt it already shows my NUC bios is the latest...what more prove do you guys need?I do not feel comfortable to share details about my used RAM, Drives and OS here

0 Kudos
Highlighted
Super User Retired Employee
76 Views

Do you want help or not? You can send it to just the ICS rep (via personal message) if you don't want it there for the public. This means, however, that volunteer experts like myself cannot help you.

...S

0 Kudos
Highlighted
Novice
72 Views

Sure, but i can't understand why you need that SSU report, there is absolutely nothing in those SSU report(s) other that then the BIOS version... It holds no information whatsoever on TXE version and/or the vulnerability(s?) reported by both, CSME Version Detection Tool 3.1.0.0 and CSME Version Detection Tool 4.0.1.0....

0 Kudos
Highlighted
Novice
57 Views

FYI, there is something weird going on with SSU, on the NUC6CAYH the BIOS Mode reports 'Legacy' when connected thru a RDP connection, but when I login physically BIOS Mode reports 'EUFI'

 

0 Kudos
Highlighted
Moderator
38 Views

Hello RvdH,

We really appreciate your patience and the information provided.

I would like to inform you that we are currently investigating this matter.

I will provide an update as soon as possible in the thread.


Esteban D.

Intel Technical Support Technician  


0 Kudos
Highlighted
Novice
34 Views

OK, thanks

I saw somewhere the latest TXE firmware for 3.x is on 3.1.80.2400, as bios version 0066 is 3.1.70.2334 there seem to have quite a few patches since the latest update

0 Kudos