First published: Tue Sep 11 2018(Updated: )
A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with administrative privileges to uncover certain platform secrets via local access or to potentially execute arbitrary code.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security and Management Engine | <12.0.6 | |
Intel Server Platform Services | <4.00.04 |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03873en_us
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3643 is classified as a high severity vulnerability due to the potential for administrative access by attackers.
To fix CVE-2018-3643, update the affected Intel Converged Security and Management Engine firmware to version 11.8.55 or later, or update Intel Server Platform Services firmware to version 4.x.04 or later.
CVE-2018-3643 affects systems using specific versions of Intel Converged Security and Management Engine firmware and Intel Server Platform Services firmware.
An attacker with administrative privileges can exploit CVE-2018-3643 to gain unauthorized access to sensitive components of the affected system.
CVE-2018-3643 is primarily a firmware vulnerability related to Intel's Power Management Controller.