cbcvebase.
CVE-2018-12192
published 2019-03-14

CVE-2018-12192: Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version…

medium6.8CVSS 3.0
AVPACLPRNUINSUCHIHAH
Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.

Affected

5 ranges
VendorProductVersion rangeFixed in
intelconverged_security_management_engine_firmware>= 11.0 < 11.8.6011.8.60
intelconverged_security_management_engine_firmware>= 11.10 < 11.11.6011.11.60
intelconverged_security_management_engine_firmware>= 11.20 < 11.22.6011.22.60
intelconverged_security_management_engine_firmware>= 12.0.0 < 12.0.2012.0.20
intelserver_platform_services_firmware< sps_e5_04.00.04.393.0sps_e5_04.00.04.393.0