CVE-2018-12196: Input Validation
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-12196?
The severity of CVE-2018-12196 is medium.
What is the affected software for CVE-2018-12196?
The affected software for CVE-2018-12196 is Intel Converged Security Management Engine Firmware versions 11.0 to 11.8.60, 11.10 to 11.11.60, 11.20 to 11.22.60, and 12.0.0 to 12.0.20.
How can a privileged user exploit CVE-2018-12196?
A privileged user can potentially execute arbitrary code via local access.
Where can I find more information about CVE-2018-12196?
You can find more information about CVE-2018-12196 at the following references: [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20190318-0001/) and [Intel Security Advisory](https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.html).
What is the Common Weakness Enumeration (CWE) ID for CVE-2018-12196?
The Common Weakness Enumeration (CWE) ID for CVE-2018-12196 is 20.