First published: Thu Mar 14 2019(Updated: )
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=11.0<11.8.60 | |
Intel Converged Security Management Engine Firmware | >=11.10<11.11.60 | |
Intel Converged Security Management Engine Firmware | >=11.20<11.22.60 | |
Intel Converged Security Management Engine Firmware | >=12.0.0<12.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-12185 is a vulnerability in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 that may allow an unauthenticated user to potentially execute arbitrary code via physical access.
CVE-2018-12185 has a severity score of 6.8 (medium).
CVE-2018-12185 affects Intel Converged Security Management Engine Firmware versions 11.0 to 11.8.60, 11.10 to 11.11.60, 11.20 to 11.22.60, and 12.0.0 to 12.0.20.
CVE-2018-12185 is associated with CWE-20 (Improper Input Validation).
Yes, you can find more information about CVE-2018-12185 in the advisories from NetApp (https://security.netapp.com/advisory/ntap-20190318-0001/) and Intel (https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.html).