HIGH · 8.3

CVE-2018-3624

Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network.

Vulnerability Description

Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network.

CVSS Score

8.3

HIGH

CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
Intel2G Modem Firmware-
IntelSofia 3G-
IntelSofia 3G-R-
IntelSofia 3G-R W-
IntelXmm71Xx-
IntelXmm72Xx-
IntelXmm73Xx-
IntelXmm74Xx-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-3624?

CVE-2018-3624 is a vulnerability with a CVSS score of 8.3 (HIGH). Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network.

How severe is CVE-2018-3624?

CVE-2018-3624 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-3624?

Check the references section above for vendor advisories and patch information. Affected products include: Intel 2G Modem Firmware, Intel Sofia 3G, Intel Sofia 3G-R, Intel Sofia 3G-R W, Intel Xmm71Xx.