CVE-2018-3657: Buffer Overflow
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability CVE-2018-3657?
CVE-2018-3657 is a vulnerability in Intel AMT in Intel CSME firmware versions before version 12.0.5 that may potentially allow a privileged user to execute arbitrary code with Intel AMT execution privilege via local access.
How severe is CVE-2018-3657?
CVE-2018-3657 has a severity rating of 6.7 (high).
Which software versions are affected by CVE-2018-3657?
CVE-2018-3657 affects Intel CSME firmware versions before version 12.0.5 and Intel Active Management Technology Firmware versions up to version 12.0.5.
Are Siemens Simatic Field Pg M5, Simatic Ipc427e, Simatic Ipc477e, Simatic Ipc547e, Simatic Pc547g, Simatic Ipc627d, Simatic Ipc647d, Simatic Ipc677d, Simatic Ipc827d, Simatic Ipc847d, and Simatic Itp1000 affected by CVE-2018-3657?
No, Siemens Simatic Field Pg M5, Simatic Ipc427e, Simatic Ipc477e, Simatic Ipc547e, Simatic Pc547g, Simatic Ipc627d, Simatic Ipc647d, Simatic Ipc677d, Simatic Ipc827d, Simatic Ipc847d, and Simatic Itp1000 are not affected by CVE-2018-3657.
How can I fix CVE-2018-3657?
To fix CVE-2018-3657, it is recommended to update to Intel CSME firmware version 12.0.5 or later.