VulnerabilityModified
CVE-2018-12199
Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.
MEDIUM 6.2EPSS 0.49%
Does this matter?
Lower severity and a low EPSS score (0.49%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.
- CVSS 3.0
- 6.2 MEDIUMCVSS:3.0/AV:P/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.49% probability · 41th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- intel/converged security management engine firmware · intel/trusted execution engine firmware
- Source
- secure@intel.com
References
- https://security.netapp.com/advisory/ntap-20190318-0001/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.htmlVendor Advisory
- https://security.netapp.com/advisory/ntap-20190318-0001/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.