MEDIUM · 5.9

CVE-2018-3616

Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key vi...

Vulnerability Description

Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.

CVSS Score

5.9

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelConverged Security Management Engine Firmware>= 11.0.0, < 12.0.5
IntelActive Management Technology Firmware< 12.0.5
IntelManageability Engine Firmware>= 9.0.0.0, < 11.0
SiemensSimatic Field Pg M5 Firmware< 22.01.06
SiemensSimatic Field Pg M5-
SiemensSimatic Ipc427E Firmware< 21.01.09
SiemensSimatic Ipc427E-
SiemensSimatic Ipc477E Firmware< 21.01.09
SiemensSimatic Ipc477E-
SiemensSimatic Ipc547E Firmware< r1.30.0
SiemensSimatic Pc547E-
SiemensSimatic Pc547G Firmware< r1.23.0
SiemensSimatic Ipc547G-
SiemensSimatic Ipc627D Firmware< 19.02.11
SiemensSimatic Ipc627D-
SiemensSimatic Ipc647D Firmware< 19.01.14
SiemensSimatic Ipc647D-
SiemensSimatic Ipc677D Firmware< 19.02.11
SiemensSimatic Ipc677D-
SiemensSimatic Ipc827D Firmware< 19.02.11

References

FAQ

What is CVE-2018-3616?

CVE-2018-3616 is a vulnerability with a CVSS score of 5.9 (MEDIUM). Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key vi...

How severe is CVE-2018-3616?

CVE-2018-3616 has been rated MEDIUM with a CVSS base score of 5.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-3616?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Converged Security Management Engine Firmware, Intel Active Management Technology Firmware, Intel Manageability Engine Firmware, Siemens Simatic Field Pg M5 Firmware, Siemens Simatic Field Pg M5.