808bits

Cryptographic Module for Intel® Converged Security and Manageability Engine (CSME)

FIPS 140-2 certificate #4158 · Intel Corporation · data as of 2026-08-28
Active. Sunset date 2026-09-21, 23 days away. This is the FIPS 140-2 sunset: after it, agencies may keep the module only in existing systems.
Caveat: When operated in FIPS mode

Certificate

Certificate number4158
StandardFIPS 140-2
Statusactive
Sunset date2026-09-21
Overall level1
Module typeFirmware-Hybrid
EmbodimentMulti-Chip Stand Alone
VendorIntel Corporation · website
Hardware versions3.0
Firmware versions2.5 and 2.6

Module description

The Cryptographic Module for Intel® Converged Security and Manageability Engine(CSME) (hereafter referred to as 'the module') is classified as a multiple-chip standalone firmware-hybrid module for FIPS 140-2 purpose. The module consists of both hardware and firmware. The hardware portion is the Converged Security Engine (CSE) and the firmware portion is the crypto driver process of the Manageability Engine (ME). The two portions form the logical cryptographic boundary and they combine as Converged Security and Manageability Engine (CSME) to perform cryptographic functions within the Cannon Point PCH applications executing on the CSME.

Approved algorithms

AlgorithmCAVP certificate
AESC1769, C1770
CVLC1769, C1770
DRBGC1769, C1770
ECDSAC1769, C1770
ENT
HMACC1769, C1770
KAS-SSCA688
KBKDFC1769, C1770
KTS
KTSvendor affirmed
PBKDFvendor affirmed
RSAC1769, C1770
SHSC1769, C1770

Tested configurations

  • embedded IA-32 dedicated to support the functionality of the CSME firmware version 12.0.70.1652 running on Cannon Point PCH with Intel Whiskey Lake with device firmware version 12.0.70.1652
  • embedded IA-32 dedicated to support the functionality of the CSME firmware version 12.0.70.1652 running on Intel Cannon Point PCH with Intel Coffee Lake with device firmware version 12.0.70.1652

Validation history

DateTypeLab
2022-02-17Initialatsec information security corporation
2023-08-21Updateatsec information security corporation

Status timeline

As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.

  • 2026-08-21: first observed by this tracker, status active
  • Validation dates on record: 2022-02-17, 2023-08-21

Known CVEs in this module family (heuristic match)

Name-based association with the module's product family, not a statement about the validated boundary. See methodology.

CVECVSSSeverity
CVE-2020-122977.8HIGH
CVE-2020-123037.8HIGH
CVE-2020-245166.8MEDIUM
CVE-2020-87056.8MEDIUM
CVE-2020-87456.8MEDIUM
CVE-2020-87036.7MEDIUM
CVE-2020-87566.7MEDIUM
CVE-2020-87514.6MEDIUM
CVE-2020-87614.6MEDIUM
CVE-2020-245064.4MEDIUM
CVE-2020-245074.4MEDIUM
CVE-2022-260474.3MEDIUM

Source documents