8.2
Advisory Published
Updated

CVE-2018-3643

First published: Tue Sep 11 2018(Updated: )

A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with administrative privileges to uncover certain platform secrets via local access or to potentially execute arbitrary code.

Credit: secure@intel.com

Affected SoftwareAffected VersionHow to fix
Intel Converged Security and Management Engine<12.0.6
Intel Server Platform Services<4.00.04

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2018-3643?

    CVE-2018-3643 is classified as a high severity vulnerability due to the potential for administrative access by attackers.

  • How do I fix CVE-2018-3643?

    To fix CVE-2018-3643, update the affected Intel Converged Security and Management Engine firmware to version 11.8.55 or later, or update Intel Server Platform Services firmware to version 4.x.04 or later.

  • Which systems are affected by CVE-2018-3643?

    CVE-2018-3643 affects systems using specific versions of Intel Converged Security and Management Engine firmware and Intel Server Platform Services firmware.

  • What can an attacker do with CVE-2018-3643?

    An attacker with administrative privileges can exploit CVE-2018-3643 to gain unauthorized access to sensitive components of the affected system.

  • Is CVE-2018-3643 a hardware or software vulnerability?

    CVE-2018-3643 is primarily a firmware vulnerability related to Intel's Power Management Controller.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203