CVE-2018-12173: High severity intel s2600bp firmware vulnerability

Published Oct 10, 2018
·
Updated

Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

Affected Software

28 affected components
Intel Server Board S2600bp Firmware<00.01.0014
Intel Server Board S2600BP
Intel Server Board S2600wf Firmware<00.01.0014
Intel Server Board S2600wf
Intel Server Board S2600st Firmware<00.01.0014
Intel Server Board S2600st
Intel Server Board S2600bpr Firmware<00.01.0014
Intel Server Board S2600bpr
Intel Server Board S2600wfr Firmware<00.01.0014
Intel Server Board S2600wfr
Intel Server Board S2600str Firmware<00.01.0014
Intel Server Board S2600str
Intel Compute Module Hns2600bp Firmware<00.01.0014
Intel Compute Module Hns2600bp
Intel Compute Module Hns2600bpr Firmware<00.01.0014
Intel Compute Module Hns2600bpr
Intel Server System R2000wf Firmware<00.01.0014
Intel Server System R2000wf
Intel Server System R1000wf Firmware<00.01.0014
Intel Server System R1000wf
Intel Server System R1000wfr Firmware<00.01.0014
Intel Server System R1000wfr
Intel Server System R2000wfr Firmware<00.01.0014
Intel Server System R2000wfr
Intel Server System H2000g Firmware<00.01.0014
Intel Server System H2000g
Intel Server System H2000gr Firmware<00.01.0014
Intel Server System H2000gr

Event History

Oct 10, 2018
CVE Published
via MITRE·06:00 PM
Data Sourced
via MITRE·06:00 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2018-12173?

CVE-2018-12173 is a vulnerability in the firmware of Intel Server Board, Intel Server System, and Intel Compute Module that may allow an unauthenticated attacker to execute arbitrary code, leading to information disclosure, privilege escalation, and denial of service.

2

How does CVE-2018-12173 affect Intel Server Board S2600bp firmware?

CVE-2018-12173 affects Intel Server Board S2600bp firmware versions up to exclusive version 00.01.0014, potentially allowing an unauthenticated attacker to execute arbitrary code and gain unauthorized access.

3

How can I fix CVE-2018-12173 on Intel Server Board S2600bp firmware?

To fix CVE-2018-12173 on Intel Server Board S2600bp firmware, update to firmware version 00.01.0014 or newer.

4

What is the severity of CVE-2018-12173?

CVE-2018-12173 has a severity rating of 7.6, which is considered high.

5

Where can I find more information about CVE-2018-12173?

You can find more information about CVE-2018-12173 on the official Intel Security Center Advisory page and the Lenovo Solutions page.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203