First published: Tue Mar 12 2019(Updated: )
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=11.0<11.8.60 | |
Intel Converged Security Management Engine Firmware | >=11.10<11.11.60 | |
Intel Converged Security Management Engine Firmware | >=11.20<11.22.60 | |
Intel Converged Security Management Engine Firmware | >=12.0.0<12.0.20 | |
Intel Trusted Execution Engine Firmware | >=3.0<3.1.60 | |
Intel Trusted Execution Engine Firmware | >=4.0<4.0.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-12188 is medium with a CVSS score of 4.6.
Intel CSME versions 11.0 to 11.8.60, 11.10 to 11.11.60, 11.20 to 11.22.60, and 12.0.0 to 12.0.20, as well as Intel TXE versions 3.0 to 3.1.60 and 4.0 to 4.0.10 are affected by CVE-2018-12188.
An unauthenticated user can potentially modify data via physical access due to insufficient input validation in Intel CSME and Intel TXE.
Yes, Intel has released firmware updates to address the vulnerability in the affected versions of Intel CSME and Intel TXE. Please refer to the Intel Security Center advisory for more information.
You can find more information about CVE-2018-12188 in the NetApp security advisory and the Intel Security Center advisory.