VulnerabilityModified
CVE-2018-3629
Buffer overflow in event handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker to cause a denial of service via the same subnet.
MEDIUM 6.5EPSS 0.98%
Does this matter?
Lower severity and a low EPSS score (0.98%). Track it; it rarely justifies an emergency change on its own.
Description
Buffer overflow in event handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker to cause a denial of service via the same subnet.
- CVSS 3.1
- 6.5 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.98% probability · 60th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- intel/active management technology firmware
- Source
- secure@intel.com
References
- http://www.securitytracker.com/id/1041362Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20190327-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03868en_usThird Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.htmlVendor Advisory
- http://www.securitytracker.com/id/1041362Third Party Advisory, VDB Entry
- https://security.netapp.com/advisory/ntap-20190327-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03868en_usThird Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.