Vulnerability Description
Buffer overflow in HTTP handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker to execute arbitrary code via the same subnet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Intel | Active Management Technology Firmware | >= 3.0, <= 11.22.70 |
| Intel | Core 2 Duo | e4300 |
| Intel | Core I3 | 4000m |
| Intel | Core I5 | 4200h |
| Intel | Core I7 | 4500u |
| Intel | Core I9 | 8950hk |
| Intel | Core 2 Extreme | qx6700 |
| Intel | Core 2 Quad | q6600 |
| Intel | Core 2 Solo | su3500 |
| Intel | Core Duo | l2300 |
| Intel | Core Solo | t1250 |
| Intel | Xeon E3 1268L V5 | - |
| Intel | Xeon E3 1275 V5 | - |
| Intel | Xeon Gold | 5115 |
| Intel | Xeon Platinum | 8153 |
| Intel | Xeon Silver | 4108 |
| Intel | Xeon | w2123 |
Related Weaknesses (CWE)
References
- http://www.securitytracker.com/id/1041362Third Party AdvisoryVDB Entry
- https://security.netapp.com/advisory/ntap-20190327-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeThird Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.Vendor Advisory
- http://www.securitytracker.com/id/1041362Third Party AdvisoryVDB Entry
- https://security.netapp.com/advisory/ntap-20190327-0001/Third Party Advisory
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpeThird Party Advisory
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00112.Vendor Advisory
FAQ
What is CVE-2018-3628?
CVE-2018-3628 is a vulnerability with a CVSS score of 8.8 (HIGH). Buffer overflow in HTTP handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker ...
How severe is CVE-2018-3628?
CVE-2018-3628 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-3628?
Check the references section above for vendor advisories and patch information. Affected products include: Intel Active Management Technology Firmware, Intel Core 2 Duo, Intel Core I3, Intel Core I5, Intel Core I7.