4.4
CVE-2018-12189
- EPSS 0.12%
- Veröffentlicht 14.03.2019 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:44:43
- Quelle secure@intel.com
- Teams Watchlist Login
- Unerledigt Login
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Converged Security Management Engine Firmware Version >= 11.0 < 11.8.60
Intel ≫ Converged Security Management Engine Firmware Version >= 11.10 < 11.11.60
Intel ≫ Converged Security Management Engine Firmware Version >= 11.20 < 11.22.60
Intel ≫ Converged Security Management Engine Firmware Version >= 12.0.0 < 12.0.20
Intel ≫ Trusted Execution Engine Firmware Version >= 3.0 < 3.1.60
Intel ≫ Trusted Execution Engine Firmware Version >= 4.0 < 4.0.10
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.12% | 0.316 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 4.4 | 0.8 | 3.6 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:N/I:P/A:N
|
CWE-754 Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.