Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-3657


Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.


Published

2018-09-12T19:29:02.840

Last Modified

2024-11-21T04:05:50.857

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System siemens simatic_field_pg_m5_firmware < 22.01.06 Yes
Hardware siemens simatic_field_pg_m5 - No
Operating System siemens simatic_ipc427e_firmware < 21.01.09 Yes
Hardware siemens simatic_ipc427e - No
Operating System siemens simatic_ipc477e_firmware < 21.01.09 Yes
Hardware siemens simatic_ipc477e - No
Operating System siemens simatic_ipc547e_firmware < r1.30.0 Yes
Hardware siemens simatic_pc547e - No
Operating System siemens simatic_pc547g_firmware < r1.23.0 Yes
Hardware siemens simatic_ipc547g - No
Operating System siemens simatic_ipc627d_firmware < 19.02.11 Yes
Hardware siemens simatic_ipc627d - No
Operating System siemens simatic_ipc647d_firmware < 19.01.14 Yes
Hardware siemens simatic_ipc647d - No
Operating System siemens simatic_ipc677d_firmware < 19.02.11 Yes
Hardware siemens simatic_ipc677d - No
Operating System siemens simatic_ipc827d_firmware < 19.02.11 Yes
Hardware siemens simatic_ipc827d - No
Operating System siemens simatic_ipc847d_firmware < 19.01.14 Yes
Hardware siemens simatic_ipc847d - No
Operating System siemens simatic_itp1000_firmware < 23.01.04 Yes
Hardware siemens simatic_itp1000 - No
Application intel converged_security_management_engine_firmware < 12.0.5 Yes
Operating System intel active_management_technology_firmware < 12.0.5 Yes
Operating System intel manageability_engine_firmware < 11.0 Yes

References