CVE-2018-3657

Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.7 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
intelCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 73%
VendorProductVersion
siemenssimatic_field_pg_m5_firmware
𝑥
< 22.01.06
siemenssimatic_ipc427e_firmware
𝑥
< 21.01.09
siemenssimatic_ipc477e_firmware
𝑥
< 21.01.09
siemenssimatic_ipc547e_firmware
𝑥
< r1.30.0
siemenssimatic_pc547g_firmware
𝑥
< r1.23.0
siemenssimatic_ipc627d_firmware
𝑥
< 19.02.11
siemenssimatic_ipc647d_firmware
𝑥
< 19.01.14
siemenssimatic_ipc677d_firmware
𝑥
< 19.02.11
siemenssimatic_ipc827d_firmware
𝑥
< 19.02.11
siemenssimatic_ipc847d_firmware
𝑥
< 19.01.14
siemenssimatic_itp1000_firmware
𝑥
< 23.01.04
intelconverged_security_management_engine_firmware
11.0.0 ≤
𝑥
< 12.0.5
intelactive_management_technology_firmware
𝑥
< 12.0.5
intelmanageability_engine_firmware
9.0.0.0 ≤
𝑥
< 11.0
𝑥
= Vulnerable software versions