CVE-2018-12192
published 2019-03-14CVE-2018-12192: Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version…
medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | converged_security_management_engine_firmware | >= 11.0 < 11.8.60 | 11.8.60 |
| intel | converged_security_management_engine_firmware | >= 11.10 < 11.11.60 | 11.11.60 |
| intel | converged_security_management_engine_firmware | >= 11.20 < 11.22.60 | 11.22.60 |
| intel | converged_security_management_engine_firmware | >= 12.0.0 < 12.0.20 | 12.0.20 |
| intel | server_platform_services_firmware | < sps_e5_04.00.04.393.0 | sps_e5_04.00.04.393.0 |