First published: Thu Mar 14 2019(Updated: )
Insufficient input validation in Intel(R) AMT in Intel(R) CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20 may allow a privileged user to potentially execute arbitrary code via local access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security Management Engine Firmware | >=11.0<11.8.60 | |
Intel Converged Security Management Engine Firmware | >=11.10<11.11.60 | |
Intel Converged Security Management Engine Firmware | >=11.20<11.22.60 | |
Intel Converged Security Management Engine Firmware | >=12.0.0<12.0.20 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-12196 is medium.
The affected software for CVE-2018-12196 is Intel Converged Security Management Engine Firmware versions 11.0 to 11.8.60, 11.10 to 11.11.60, 11.20 to 11.22.60, and 12.0.0 to 12.0.20.
A privileged user can potentially execute arbitrary code via local access.
You can find more information about CVE-2018-12196 at the following references: [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20190318-0001/) and [Intel Security Advisory](https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.html).
The Common Weakness Enumeration (CWE) ID for CVE-2018-12196 is 20.