CVE-2018-12191
Summary
| CVE | CVE-2018-12191 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-03-14 20:29:00 UTC |
| Updated | 2020-09-10 13:19:00 UTC |
| Description | Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access. |
Risk And Classification
Problem Types: CWE-119
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Intel | Converged Security Management Engine Firmware | All | All | All | All |
| Operating System | Intel | Converged Security Management Engine Firmware | All | All | All | All |
| Operating System | Intel | Server Platform Services Firmware | All | All | All | All |
| Operating System | Intel | Server Platform Services Firmware | All | All | All | All |
| Operating System | Intel | Trusted Execution Engine Firmware | All | All | All | All |
| Operating System | Intel | Trusted Execution Engine Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| INTEL-SA-00185 | CONFIRM | www.intel.com | Vendor Advisory |
| Document Display | HPE Support Center | CONFIRM | support.hpe.com | Third Party Advisory |
| Intel SA-00185 CSME-SPS-TXE-AMT Vulnerabilities in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.