VulnerabilityModified
CVE-2018-3659
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
MEDIUM 6.8EPSS 0.41%
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
- CVSS 3.0
- 6.8 MEDIUMCVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Affected
- intel/converged security management engine firmware · intel/trusted execution engine firmware
- Source
- secure@intel.com
References
- https://security.netapp.com/advisory/ntap-20180924-0003/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00142.htmlVendor Advisory
- https://security.netapp.com/advisory/ntap-20180924-0003/Third Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00142.htmlVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.