MEDIUM · 6.8

CVE-2018-12205

Improper certificate validation in Platform Sample/ Silicon Reference firmware for 8th Generation Intel(R) Core(tm) Processor, 7th Generation Intel(R) Core(tm) Processor may allow an unauthenticated u...

Vulnerability Description

Improper certificate validation in Platform Sample/ Silicon Reference firmware for 8th Generation Intel(R) Core(tm) Processor, 7th Generation Intel(R) Core(tm) Processor may allow an unauthenticated user to potentially enable an escalation of privilege via physical access.

CVSS Score

6.8

MEDIUM

CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
PHYSICAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelPlatform Sample Firmware-
IntelCore I38100
IntelCore I58200y
IntelCore I78086k
IntelSilicon Reference Firmware-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-12205?

CVE-2018-12205 is a vulnerability with a CVSS score of 6.8 (MEDIUM). Improper certificate validation in Platform Sample/ Silicon Reference firmware for 8th Generation Intel(R) Core(tm) Processor, 7th Generation Intel(R) Core(tm) Processor may allow an unauthenticated u...

How severe is CVE-2018-12205?

CVE-2018-12205 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-12205?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Platform Sample Firmware, Intel Core I3, Intel Core I5, Intel Core I7, Intel Silicon Reference Firmware.