Cryptographic Module for Intel® Converged Security and Manageability Engine (CSME)
Cryptographic Module for Intel® Converged Security and Manageability Engine (CSME), from Intel Corporation, holds FIPS 140-2 certificate #4158 at overall level 1. The validation is active, with a sunset date of 2026-09-21. Below are its validation history, algorithm certificates and security policy, drawn from the NIST CMVP entry.
Caveat: When operated in FIPS mode
Certificate
| Certificate number | 4158 |
|---|---|
| Standard | FIPS 140-2 |
| Status | active |
| Sunset date | 2026-09-21 |
| Overall level | 1 |
| Module type | Firmware-Hybrid |
| Embodiment | Multi-Chip Stand Alone |
| Vendor | Intel Corporation · website |
| Hardware versions | 3.0 |
| Firmware versions | 2.5 and 2.6 |
Module description
Quoted from the NIST CMVP entry for this certificate.
The Cryptographic Module for Intel® Converged Security and Manageability Engine(CSME) (hereafter referred to as 'the module') is classified as a multiple-chip standalone firmware-hybrid module for FIPS 140-2 purpose. The module consists of both hardware and firmware. The hardware portion is the Converged Security Engine (CSE) and the firmware portion is the crypto driver process of the Manageability Engine (ME). The two portions form the logical cryptographic boundary and they combine as Converged Security and Manageability Engine (CSME) to perform cryptographic functions within the Cannon Point PCH applications executing on the CSME.
Approved algorithms (12)
| Algorithm | CAVP certificates |
|---|---|
| AES | C1769, C1770 |
| CVL | C1769, C1770 |
| DRBG | C1769, C1770 |
| ECDSA | C1769, C1770 |
| ENT | |
| HMAC | C1769, C1770 |
| KAS-SSC | A688 |
| KBKDF | C1769, C1770 |
| KTS | vendor affirmed |
| PBKDF | vendor affirmed |
| RSA | C1769, C1770 |
| SHS | C1769, C1770 |
Tested configurations
- embedded IA-32 dedicated to support the functionality of the CSME firmware version 12.0.70.1652 running on Cannon Point PCH with Intel Whiskey Lake with device firmware version 12.0.70.1652
- embedded IA-32 dedicated to support the functionality of the CSME firmware version 12.0.70.1652 running on Intel Cannon Point PCH with Intel Coffee Lake with device firmware version 12.0.70.1652
Validation history
| Date | Type | Lab |
|---|---|---|
| 2022-02-17 | Initial | atsec information security corporation |
| 2023-08-21 | Update | atsec information security corporation |
Status timeline
As observed by this tracker's snapshots. NIST publishes no dates for list moves; observation began 2026-08-21, so earlier changes carry no date.
- 2026-08-21: first observed by this tracker, status active
- Validation dates on record: 2022-02-17, 2023-08-21
Known CVEs in this module family (heuristic match)
Name-based association with the module's product family, not a statement about the validated boundary. See methodology.
| CVE | CVSS | Severity |
|---|---|---|
| CVE-2020-12297 | 7.8 | HIGH |
| CVE-2020-12303 | 7.8 | HIGH |
| CVE-2020-24516 | 6.8 | MEDIUM |
| CVE-2020-8705 | 6.8 | MEDIUM |
| CVE-2020-8745 | 6.8 | MEDIUM |
| CVE-2020-8703 | 6.7 | MEDIUM |
| CVE-2020-8756 | 6.7 | MEDIUM |
| CVE-2020-8751 | 4.6 | MEDIUM |
| CVE-2020-8761 | 4.6 | MEDIUM |
| CVE-2020-24506 | 4.4 | MEDIUM |
| CVE-2020-24507 | 4.4 | MEDIUM |
| CVE-2022-26047 | 4.3 | MEDIUM |