CVE-2018-3652: Infoleak
Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3652?
CVE-2018-3652 has been assigned a medium severity rating, indicating a moderate level of risk to systems.
How do I fix CVE-2018-3652?
To mitigate CVE-2018-3652, users should apply the firmware updates provided by Intel for the affected Intel Xeon processors.
What are the affected Intel Xeon processors in CVE-2018-3652?
CVE-2018-3652 affects 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family.
What type of attack does CVE-2018-3652 enable?
CVE-2018-3652 allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.
Is CVE-2018-3652 a local or remote vulnerability?
CVE-2018-3652 is considered a local vulnerability as it requires physical access to the affected systems.