CVE-2018-3658
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
12/09/2018
Last modified:
17/08/2023
Description
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:* | 22.01.06 (excluding) | |
| cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:* | 21.01.09 (excluding) | |
| cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:* | 21.01.09 (excluding) | |
| cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc547e_firmware:*:*:*:*:*:*:*:* | r1.30.0 (excluding) | |
| cpe:2.3:h:siemens:simatic_pc547e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_pc547g_firmware:*:*:*:*:*:*:*:* | r1.23.0 (excluding) | |
| cpe:2.3:h:siemens:simatic_ipc547g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc627d_firmware:*:*:*:*:*:*:*:* | 19.02.11 (excluding) | |
| cpe:2.3:h:siemens:simatic_ipc627d:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc647d_firmware:*:*:*:*:*:*:*:* | 19.01.14 (excluding) | |
| cpe:2.3:h:siemens:simatic_ipc647d:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:siemens:simatic_ipc677d_firmware:*:*:*:*:*:*:*:* | 19.02.11 (excluding) |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.securityfocus.com/bid/106996
- https://cert-portal.siemens.com/productcert/pdf/ssa-377318.pdf
- https://ics-cert.us-cert.gov/advisories/ICSA-19-043-05
- https://security.netapp.com/advisory/ntap-20180924-0003/
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03876en_us
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00141.html



