CVE-2018-3655

A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.3 HIGH
PHYSICAL
LOW
NONE
CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
intelCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 40%
VendorProductVersion
intelconverged_security_management_engine_firmware
11.0 ≤
𝑥
≤ 11.8.50
intelconverged_security_management_engine_firmware
11.10 ≤
𝑥
≤ 11.11.50
intelconverged_security_management_engine_firmware
11.20 ≤
𝑥
≤ 11.21.51
intelserver_platform_services_firmware
𝑥
< 4.0
inteltrusted_execution_engine_firmware
3.0 ≤
𝑥
≤ 3.1.50
𝑥
= Vulnerable software versions