CVE-2018-3658
published 2018-09-12CVE-2018-3658: Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially…
PriorityP429medium5.3CVSS 3.1
AVNACLPRNUINSUCNINAL
EPSS
3.30%
87.1th percentile
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | active_management_technology_firmware | < 12.0.5 | 12.0.5 |
| intel | converged_security_management_engine_firmware | >= 11.0.0 < 12.0.5 | 12.0.5 |
| intel | manageability_engine_firmware | >= 9.0.0.0 < 11.0 | 11.0 |
| intel_corporation | intel_active_management_technology | — | — |
| siemens | simatic_field_pg_m5_firmware | < 22.01.06 | 22.01.06 |
| siemens | simatic_ipc427e_firmware | < 21.01.09 | 21.01.09 |
| siemens | simatic_ipc477e_firmware | < 21.01.09 | 21.01.09 |
| siemens | simatic_ipc547e_firmware | < r1.30.0 | r1.30.0 |
| siemens | simatic_ipc627d_firmware | < 19.02.11 | 19.02.11 |
| siemens | simatic_ipc647d_firmware | < 19.01.14 | 19.01.14 |
| siemens | simatic_ipc677d_firmware | < 19.02.11 | 19.02.11 |
| siemens | simatic_ipc827d_firmware | < 19.02.11 | 19.02.11 |
| siemens | simatic_ipc847d_firmware | < 19.01.14 | 19.01.14 |
| siemens | simatic_itp1000_firmware | < 23.01.04 | 23.01.04 |
| siemens | simatic_pc547g_firmware | < r1.23.0 | r1.23.0 |
CVSS provenance
nvdv3.15.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4xf8-qhpw-9g4c: Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12
ghsa_unreviewed·2022-05-13
CVE-2018-3658 [MEDIUM] CWE-772 GHSA-4xf8-qhpw-9g4c: Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12
Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
CISA ICS
Siemens Intel Active Management Technology of SIMATIC IPCs
cisa_ics·2019-02-12·CVSS 5.9
[MEDIUM] Siemens Intel Active Management Technology of SIMATIC IPCs
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Intel Active Management Technology of SIMATIC IPCs
Last RevisedFebruary 12, 2019
Alert CodeICSA-19-043-05
## 1. EXECUTIVE SUMMARY
-
CVSS v3 6.7
- ATTENTION: Exploitable remotely/low skill level to exploit
- Vendor: Siemens
- Equipment: Intel Active Management Technology (AMT) of SIMATIC IPCs
- Vulnerabilities: Cryptographic Issues, Improper Restriction of Operations within the Bounds of a Memory Buffer, Resource Management Errors
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow arbitrary code execution, a partial denial-of-service co
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/106996https://cert-portal.siemens.com/productcert/pdf/ssa-377318.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-19-043-05https://security.netapp.com/advisory/ntap-20180924-0003/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03876en_ushttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00141.htmlhttp://www.securityfocus.com/bid/106996https://cert-portal.siemens.com/productcert/pdf/ssa-377318.pdfhttps://ics-cert.us-cert.gov/advisories/ICSA-19-043-05https://security.netapp.com/advisory/ntap-20180924-0003/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03876en_ushttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00141.html
2018-09-12
Published