CVE-2018-3655: High severity intel converged security and management engine vulnerability
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3655?
CVE-2018-3655 is considered a high severity vulnerability due to the potential for unauthorized information disclosure or modification.
How do I fix CVE-2018-3655?
To address CVE-2018-3655, update to the latest versions of Intel CSME, Intel Server Platform Services, and Intel Trusted Execution Engine Firmware as specified by vendor advisories.
Who is affected by CVE-2018-3655?
CVE-2018-3655 affects users running outdated versions of Intel CSME, Intel Server Platform Services, and Intel Trusted Execution Engine Firmware.
What types of attacks can exploit CVE-2018-3655?
CVE-2018-3655 can be exploited by an unauthenticated user with physical access to modify or disclose sensitive information.
When was CVE-2018-3655 disclosed?
CVE-2018-3655 was publicly disclosed in September 2018.