First published: Wed Sep 12 2018(Updated: )
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel Converged Security and Management Engine | >=11.0<=11.8.50 | |
Intel Converged Security and Management Engine | >=11.10<=11.11.50 | |
Intel Converged Security and Management Engine | >=11.20<=11.21.51 | |
Intel Server Platform Services | <4.0 | |
Intel Trusted Execution Engine | >=3.0<=3.1.50 |
https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03873en_us
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3655 is considered a high severity vulnerability due to the potential for unauthorized information disclosure or modification.
To address CVE-2018-3655, update to the latest versions of Intel CSME, Intel Server Platform Services, and Intel Trusted Execution Engine Firmware as specified by vendor advisories.
CVE-2018-3655 affects users running outdated versions of Intel CSME, Intel Server Platform Services, and Intel Trusted Execution Engine Firmware.
CVE-2018-3655 can be exploited by an unauthenticated user with physical access to modify or disclose sensitive information.
CVE-2018-3655 was publicly disclosed in September 2018.