cbcvebase.
CVE-2018-3616
published 2018-09-12

CVE-2018-3616: Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to…

PriorityP431medium5.9CVSS 3.1
AVNACHPRNUINSUCHINAN
EPSS
2.39%
82.0th percentile
Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.

Affected

15 ranges
VendorProductVersion rangeFixed in
intelactive_management_technology_firmware< 12.0.512.0.5
intelconverged_security_management_engine_firmware>= 11.0.0 < 12.0.512.0.5
intelmanageability_engine_firmware>= 9.0.0.0 < 11.011.0
intel_corporationintel_active_management_technology
siemenssimatic_field_pg_m5_firmware< 22.01.0622.01.06
siemenssimatic_ipc427e_firmware< 21.01.0921.01.09
siemenssimatic_ipc477e_firmware< 21.01.0921.01.09
siemenssimatic_ipc547e_firmware< r1.30.0r1.30.0
siemenssimatic_ipc627d_firmware< 19.02.1119.02.11
siemenssimatic_ipc647d_firmware< 19.01.1419.01.14
siemenssimatic_ipc677d_firmware< 19.02.1119.02.11
siemenssimatic_ipc827d_firmware< 19.02.1119.02.11
siemenssimatic_ipc847d_firmware< 19.01.1419.01.14
siemenssimatic_itp1000_firmware< 23.01.0423.01.04
siemenssimatic_pc547g_firmware< r1.23.0r1.23.0

CVSS provenance

nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.