HIGH · 8.8

CVE-2018-3628

Buffer overflow in HTTP handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker ...

Vulnerability Description

Buffer overflow in HTTP handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker to execute arbitrary code via the same subnet.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelActive Management Technology Firmware>= 3.0, <= 11.22.70
IntelCore 2 Duoe4300
IntelCore I34000m
IntelCore I54200h
IntelCore I74500u
IntelCore I98950hk
IntelCore 2 Extremeqx6700
IntelCore 2 Quadq6600
IntelCore 2 Solosu3500
IntelCore Duol2300
IntelCore Solot1250
IntelXeon E3 1268L V5-
IntelXeon E3 1275 V5-
IntelXeon Gold5115
IntelXeon Platinum8153
IntelXeon Silver4108
IntelXeonw2123

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-3628?

CVE-2018-3628 is a vulnerability with a CVSS score of 8.8 (HIGH). Buffer overflow in HTTP handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker ...

How severe is CVE-2018-3628?

CVE-2018-3628 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-3628?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Active Management Technology Firmware, Intel Core 2 Duo, Intel Core I3, Intel Core I5, Intel Core I7.