CVE-2018-12192

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
14/03/2019
Last modified:
04/04/2019

Description

Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* 11.0 (including) 11.8.60 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* 11.10 (including) 11.11.60 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* 11.20 (including) 11.22.60 (excluding)
cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:* 12.0.0 (including) 12.0.20 (excluding)
cpe:2.3:o:intel:server_platform_services_firmware:*:*:*:*:*:*:*:* sps_e5_04.00.04.393.0 (excluding)