VulnerabilityModified
CVE-2018-18095
Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user to potentially enable escalation of privilege via physical access.
MEDIUM 6.8EPSS 0.52%
Does this matter?
Lower severity and a low EPSS score (0.52%). Track it; it rarely justifies an emergency change on its own.
Description
Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user to potentially enable escalation of privilege via physical access.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.52% probability · 42th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- intel/ssd dc s4500 firmware · intel/ssd dc s4600 firmware
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/109103Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K62655863
- https://support.f5.com/csp/article/K62655863?utm_source=f5support&%3Butm_medium=RSS
- https://support.lenovo.com/us/en/product_security/LEN-28116Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00267.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/109103Third Party Advisory, VDB Entry
- https://support.f5.com/csp/article/K62655863
- https://support.f5.com/csp/article/K62655863?utm_source=f5support&%3Butm_medium=RSS
- https://support.lenovo.com/us/en/product_security/LEN-28116Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00267.htmlPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.