8.2
CVE-2018-3643
- EPSS 0.21%
- Veröffentlicht 12.09.2018 19:29:02
- Zuletzt bearbeitet 21.11.2024 04:05:49
- Quelle secure@intel.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with administrative privileges to uncover certain platform secrets via local access or to potentially execute arbitrary code.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Intel ≫ Converged Security Management Engine Firmware Version < 12.0.6
Intel ≫ Server Platform Services Firmware Version < 4.00.04
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.433 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 8.2 | 1.5 | 6 |
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
|
nvd@nist.gov | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|