First published: Wed Oct 10 2018(Updated: )
Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Server Board S2600bp Firmware | <00.01.0014 | |
Intel Server Board S2600bp | ||
Intel Server Board S2600wf Firmware | <00.01.0014 | |
Intel Server Board S2600wf | ||
Intel Server Board S2600st Firmware | <00.01.0014 | |
Intel Server Board S2600st | ||
Intel Server Board S2600bpr Firmware | <00.01.0014 | |
Intel Server Board S2600bpr | ||
Intel Server Board S2600wfr Firmware | <00.01.0014 | |
Intel Server Board S2600wfr | ||
Intel Server Board S2600str Firmware | <00.01.0014 | |
Intel Server Board S2600str | ||
Intel Compute Module Hns2600bp Firmware | <00.01.0014 | |
Intel Compute Module Hns2600bp | ||
Intel Compute Module Hns2600bpr Firmware | <00.01.0014 | |
Intel Compute Module Hns2600bpr | ||
Intel Server System R2000wf Firmware | <00.01.0014 | |
Intel Server System R2000wf | ||
Intel Server System R1000wf Firmware | <00.01.0014 | |
Intel Server System R1000wf | ||
Intel Server System R1000wfr Firmware | <00.01.0014 | |
Intel Server System R1000wfr | ||
Intel Server System R2000wfr Firmware | <00.01.0014 | |
Intel Server System R2000wfr | ||
Intel Server System H2000g Firmware | <00.01.0014 | |
Intel Server System H2000g | ||
Intel Server System H2000gr Firmware | <00.01.0014 | |
Intel Server System H2000gr |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12173 is a vulnerability in the firmware of Intel Server Board, Intel Server System, and Intel Compute Module that may allow an unauthenticated attacker to execute arbitrary code, leading to information disclosure, privilege escalation, and denial of service.
CVE-2018-12173 affects Intel Server Board S2600bp firmware versions up to exclusive version 00.01.0014, potentially allowing an unauthenticated attacker to execute arbitrary code and gain unauthorized access.
To fix CVE-2018-12173 on Intel Server Board S2600bp firmware, update to firmware version 00.01.0014 or newer.
CVE-2018-12173 has a severity rating of 7.6, which is considered high.
You can find more information about CVE-2018-12173 on the official Intel Security Center Advisory page and the Lenovo Solutions page.