Intel® Converged Security and Manageability Engine (CSME) Crypto Module for Tiger Point PCH, Mule Creek Canyon PCH, and Rocket Lake PCH
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 4150 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Firmware-Hybrid |
| Embodiment | Single Chip |
| Vendor | Intel Corporation · website |
| Hardware versions | 4.0 |
| Firmware versions | 4.0[1], 4.1[2], 4.2[3] and 4.3[4] |
Module description
Intel® Converged Security and Manageability Engine (CSME) Crypto Module for Tiger Point PCH, Mule Creek Canyon PCH, and Rocket Lake PCH is as a firmware-hybrid cryptographic module. The module consists of both hardware and firmware. The hardware portion is the Offload and Cryptography Subsystem (OCS) and the firmware portion is the Converged Security and Manageability Engine (CSME) Crypto Driver firmware.
Approved algorithms
| Algorithm | CAVP certificate |
|---|---|
| AES | A667, A668 |
| DRBG | A667 |
| ECDSA | A667, A668 |
| ENT | |
| HMAC | A668 |
| KAS | vendor affirmed |
| KAS-SSC | A667 |
| KBKDF | A667 |
| KDA | vendor affirmed |
| KTS | vendor affirmed |
| PBKDF | vendor affirmed |
| RSA | A667 |
| SHS | A668 |
Tested configurations
- Embedded customized proprietary OS running firmware version 15.0.20.1648 on Intel Tiger Point PCH for Intel Tiger Lake-U with Lakemont 3.7[1]
- Embedded customized proprietary OS running firmware version 15.0.22.1571 on Intel Rocket Lake PCH for Intel Rocket Lake-S with Lakemont 3.7[2]
- Embedded customized proprietary OS running firmware version 15.0.30.1716 on Intel Tiger Point PCH for Intel Tiger Lake-H with Lakemont 3.7[3]
- Embedded customized proprietary OS running firmware version 15.40.10.2204 on Intel Mule Creek Canyon PCH for Intel Elkhart Lake with Lakemont 3.7[4]
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-02-10 | Initial | atsec information security corporation |
| 2023-08-17 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-02-10, 2023-08-17
Known CVEs in this module family (heuristic match)
Name-based association with the module's product family, not a statement about the validated boundary. See methodology.
| CVE | CVSS | Severity |
|---|---|---|
| CVE-2020-12297 | 7.8 | HIGH |
| CVE-2020-12303 | 7.8 | HIGH |
| CVE-2020-24516 | 6.8 | MEDIUM |
| CVE-2020-8705 | 6.8 | MEDIUM |
| CVE-2020-8745 | 6.8 | MEDIUM |
| CVE-2020-8703 | 6.7 | MEDIUM |
| CVE-2020-8756 | 6.7 | MEDIUM |
| CVE-2020-8751 | 4.6 | MEDIUM |
| CVE-2020-8761 | 4.6 | MEDIUM |
| CVE-2020-24506 | 4.4 | MEDIUM |
| CVE-2020-24507 | 4.4 | MEDIUM |
| CVE-2022-26047 | 4.3 | MEDIUM |