CVE-2018-12188
Summary
| CVE | CVE-2018-12188 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-14 20:29:00 UTC |
| Updated | 2019-03-21 16:00:00 UTC |
| Description | Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Intel | Converged Security Management Engine Firmware | All | All | All | All |
| Operating System | Intel | Converged Security Management Engine Firmware | All | All | All | All |
| Operating System | Intel | Trusted Execution Engine Firmware | All | All | All | All |
| Operating System | Intel | Trusted Execution Engine Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| INTEL-SA-00185 | CONFIRM | www.intel.com | Vendor Advisory |
| Intel SA-00185 CSME-SPS-TXE-AMT Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.