8.2

CVE-2018-3682

BMC Firmware in Intel server boards, compute modules, and systems potentially allow an attacker with administrative privileges to make unauthorized read\writes to the SMBUS.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IntelBmc Firmware Version-
   IntelBbs2600bpb Version-
   IntelBbs2600bpq Version-
   IntelBbs2600bps Version-
   IntelBbs2600stb Version-
   IntelBbs2600stq Version-
   IntelBbs7200ap Version-
   IntelBbs7200apl Version-
   IntelDbs2600cw2r Version-
   IntelDbs2600cw2sr Version-
   IntelDbs2600cwtr Version-
   IntelDbs2600cwtsr Version-
   IntelHns2600bpb Version-
   IntelHns2600bpb24 Version-
   IntelHns2600bpblc Version-
   IntelHns2600bpblc24 Version-
   IntelHns2600bpq Version-
   IntelHns2600bpq24 Version-
   IntelHns2600bps Version-
   IntelHns2600bps24 Version-
   IntelHns2600kpfr Version-
   IntelHns2600kpr Version-
   IntelHns2600tp24r Version-
   IntelHns2600tp24sr Version-
   IntelHns2600tp24str Version-
   IntelHns2600tpfr Version-
   IntelHns2600tpnr Version-
   IntelHns2600tpr Version-
   IntelHns7200ap Version-
   IntelHns7200apl Version-
   IntelHns7200apr Version-
   IntelHns7200aprl Version-
   IntelR1208wftys Version-
   IntelR1208wt2gsr Version-
   IntelR1208wttgsr Version-
   IntelR1304wf0ys Version-
   IntelR1304wftys Version-
   IntelR1304wt2gsr Version-
   IntelR1304wttgsr Version-
   IntelR2208wf0zs Version-
   IntelR2208wfqzs Version-
   IntelR2208wftzs Version-
   IntelR2208wt2ysr Version-
   IntelR2208wttyc1r Version-
   IntelR2208wttysr Version-
   IntelR2224wfqzs Version-
   IntelR2224wftzs Version-
   IntelR2224wttysr Version-
   IntelR2308wftzs Version-
   IntelR2308wttysr Version-
   IntelR2312wf0np Version-
   IntelR2312wfqzs Version-
   IntelR2312wftzs Version-
   IntelR2312wttysr Version-
   IntelS2600kpfr Version-
   IntelS2600kpr Version-
   IntelS2600kptr Version-
   IntelS2600stb Version-
   IntelS2600stq Version-
   IntelS2600tpfr Version-
   IntelS2600tpnr Version-
   IntelS2600tpr Version-
   IntelS2600tptr Version-
   IntelS2600wfo Version-
   IntelS2600wfq Version-
   IntelS2600wft Version-
   IntelS2600wt2r Version-
   IntelS2600wttr Version-
   IntelS2600wtts1r Version-
   IntelS7200apr Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.05% 0.113
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.2 1.5 6
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.