808bits

Intel® Converged Security and Manageability Engine (CSME) Crypto Module for Tiger Point PCH, Mule Creek Canyon PCH, and Rocket Lake PCH

FIPS 140-2 certificate #4150 · Intel Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode

Certificate

Certificate number4150
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeFirmware-Hybrid
EmbodimentSingle Chip
VendorIntel Corporation · website
Hardware versions4.0
Firmware versions4.0[1], 4.1[2], 4.2[3] and 4.3[4]

Module description

Intel® Converged Security and Manageability Engine (CSME) Crypto Module for Tiger Point PCH, Mule Creek Canyon PCH, and Rocket Lake PCH is as a firmware-hybrid cryptographic module. The module consists of both hardware and firmware. The hardware portion is the Offload and Cryptography Subsystem (OCS) and the firmware portion is the Converged Security and Manageability Engine (CSME) Crypto Driver firmware.

Approved algorithms

AlgorithmCAVP certificate
AESA667, A668
DRBGA667
ECDSAA667, A668
ENT
HMACA668
KASvendor affirmed
KAS-SSCA667
KBKDFA667
KDAvendor affirmed
KTSvendor affirmed
PBKDFvendor affirmed
RSAA667
SHSA668

Tested configurations

  • Embedded customized proprietary OS running firmware version 15.0.20.1648 on Intel Tiger Point PCH for Intel Tiger Lake-U with Lakemont 3.7[1]
  • Embedded customized proprietary OS running firmware version 15.0.22.1571 on Intel Rocket Lake PCH for Intel Rocket Lake-S with Lakemont 3.7[2]
  • Embedded customized proprietary OS running firmware version 15.0.30.1716 on Intel Tiger Point PCH for Intel Tiger Lake-H with Lakemont 3.7[3]
  • Embedded customized proprietary OS running firmware version 15.40.10.2204 on Intel Mule Creek Canyon PCH for Intel Elkhart Lake with Lakemont 3.7[4]

Validation history

DateTypeLab
2022-02-10Initialatsec information security corporation
2023-08-17Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-02-10, 2023-08-17

Known CVEs in this module family (heuristic match)

Name-based association with the module's product family, not a statement about the validated boundary. See methodology.

CVECVSSSeverity
CVE-2020-122977.8HIGH
CVE-2020-123037.8HIGH
CVE-2020-245166.8MEDIUM
CVE-2020-87056.8MEDIUM
CVE-2020-87456.8MEDIUM
CVE-2020-87036.7MEDIUM
CVE-2020-87566.7MEDIUM
CVE-2020-87514.6MEDIUM
CVE-2020-87614.6MEDIUM
CVE-2020-245064.4MEDIUM
CVE-2020-245074.4MEDIUM
CVE-2022-260474.3MEDIUM

Source documents