7.2

CVE-2018-3657

Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SiemensSimatic Field Pg M5 Firmware Version < 22.01.06
   SiemensSimatic Field Pg M5 Version-
SiemensSimatic Ipc427e Firmware Version < 21.01.09
   SiemensSimatic Ipc427e Version-
SiemensSimatic Ipc477e Firmware Version < 21.01.09
   SiemensSimatic Ipc477e Version-
SiemensSimatic Ipc547e Firmware Version < r1.30.0
   SiemensSimatic Pc547e Version-
SiemensSimatic Pc547g Firmware Version < r1.23.0
   SiemensSimatic Ipc547g Version-
SiemensSimatic Ipc627d Firmware Version < 19.02.11
   SiemensSimatic Ipc627d Version-
SiemensSimatic Ipc647d Firmware Version < 19.01.14
   SiemensSimatic Ipc647d Version-
SiemensSimatic Ipc677d Firmware Version < 19.02.11
   SiemensSimatic Ipc677d Version-
SiemensSimatic Ipc827d Firmware Version < 19.02.11
   SiemensSimatic Ipc827d Version-
SiemensSimatic Ipc847d Firmware Version < 19.01.14
   SiemensSimatic Ipc847d Version-
SiemensSimatic Itp1000 Firmware Version < 23.01.04
   SiemensSimatic Itp1000 Version-
IntelManageability Engine Firmware Version >= 9.0.0.0 < 11.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.26% 0.496
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.