CVE-2018-12191
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
La comprobación de límites en el subsistema del kernel en Intel CSME, en versiones anteriores a las 11.8.60, 11.11.60, 11.22.60 o 12.0.20; o Intel(R) Server Platform Services, en versiones anteriores a la 4.00.04.383 o SPS 4.01.02.174; o Intel(R) TXE, en versiones anteriores a la 3.1.60 o 4.0.10, podría permitir que un usuario no autenticado pueda ejecutar código arbitrario mediante acceso físico.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-06-11 CVE Reserved
- 2019-03-14 CVE Published
- 2024-03-05 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://security.netapp.com/advisory/ntap-20190318-0001 | Third Party Advisory | |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03914en_us | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.html | 2020-09-10 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Intel Search vendor "Intel" | Converged Security Management Engine Firmware Search vendor "Intel" for product "Converged Security Management Engine Firmware" | >= 11.0 < 11.8.60 Search vendor "Intel" for product "Converged Security Management Engine Firmware" and version " >= 11.0 < 11.8.60" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security Management Engine Firmware Search vendor "Intel" for product "Converged Security Management Engine Firmware" | >= 11.10 < 11.11.60 Search vendor "Intel" for product "Converged Security Management Engine Firmware" and version " >= 11.10 < 11.11.60" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security Management Engine Firmware Search vendor "Intel" for product "Converged Security Management Engine Firmware" | >= 11.20 < 11.22.60 Search vendor "Intel" for product "Converged Security Management Engine Firmware" and version " >= 11.20 < 11.22.60" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Converged Security Management Engine Firmware Search vendor "Intel" for product "Converged Security Management Engine Firmware" | >= 12.0.0 < 12.0.20 Search vendor "Intel" for product "Converged Security Management Engine Firmware" and version " >= 12.0.0 < 12.0.20" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Server Platform Services Firmware Search vendor "Intel" for product "Server Platform Services Firmware" | >= 4.00.04.367 < 4.00.04.383 Search vendor "Intel" for product "Server Platform Services Firmware" and version " >= 4.00.04.367 < 4.00.04.383" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Server Platform Services Firmware Search vendor "Intel" for product "Server Platform Services Firmware" | >= 4.01.00.152.0 < 4.01.02.174 Search vendor "Intel" for product "Server Platform Services Firmware" and version " >= 4.01.00.152.0 < 4.01.02.174" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Trusted Execution Engine Firmware Search vendor "Intel" for product "Trusted Execution Engine Firmware" | >= 3.0 < 3.1.60 Search vendor "Intel" for product "Trusted Execution Engine Firmware" and version " >= 3.0 < 3.1.60" | - |
Affected
| ||||||
Intel Search vendor "Intel" | Trusted Execution Engine Firmware Search vendor "Intel" for product "Trusted Execution Engine Firmware" | >= 4.0 < 4.0.10 Search vendor "Intel" for product "Trusted Execution Engine Firmware" and version " >= 4.0 < 4.0.10" | - |
Affected
|