Vulnerability Description
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Server Board S2600Bp Firmware | < 00.01.0014 |
| Intel | Server Board S2600Bp | - |
| Intel | Server Board S2600Wf Firmware | < 00.01.0014 |
| Intel | Server Board S2600Wf | - |
| Intel | Server Board S2600St Firmware | < 00.01.0014 |
| Intel | Server Board S2600St | - |
| Intel | Server Board S2600Bpr Firmware | < 00.01.0014 |
| Intel | Server Board S2600Bpr | - |
| Intel | Server Board S2600Wfr Firmware | < 00.01.0014 |
| Intel | Server Board S2600Wfr | - |
| Intel | Server Board S2600Str Firmware | < 00.01.0014 |
| Intel | Server Board S2600Str | - |
| Intel | Compute Module Hns2600Bp Firmware | < 00.01.0014 |
| Intel | Compute Module Hns2600Bp | - |
| Intel | Compute Module Hns2600Bpr Firmware | < 00.01.0014 |
| Intel | Compute Module Hns2600Bpr | - |
| Intel | Server System R2000Wf Firmware | < 00.01.0014 |
| Intel | Server System R2000Wf | - |
| Intel | Server System R1000Wf Firmware | < 00.01.0014 |
| Intel | Server System R1000Wf | - |
Related Weaknesses (CWE)
References
- http://support.lenovo.com/us/en/solutions/LEN-24799
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00179.Vendor Advisory
- http://support.lenovo.com/us/en/solutions/LEN-24799
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00179.Vendor Advisory
FAQ
What is CVE-2018-12173?
CVE-2018-12173 is a vulnerability with a CVSS score of 7.6 (HIGH). Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially e...
How severe is CVE-2018-12173?
CVE-2018-12173 has been rated HIGH with a CVSS base score of 7.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-12173?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Server Board S2600Bp Firmware, Intel Server Board S2600Bp, Intel Server Board S2600Wf Firmware, Intel Server Board S2600Wf, Intel Server Board S2600St Firmware.