CVE-2018-3658

Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.3 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
intelCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 77%
VendorProductVersion
siemenssimatic_field_pg_m5_firmware
𝑥
< 22.01.06
siemenssimatic_ipc427e_firmware
𝑥
< 21.01.09
siemenssimatic_ipc477e_firmware
𝑥
< 21.01.09
siemenssimatic_ipc547e_firmware
𝑥
< r1.30.0
siemenssimatic_pc547g_firmware
𝑥
< r1.23.0
siemenssimatic_ipc627d_firmware
𝑥
< 19.02.11
siemenssimatic_ipc647d_firmware
𝑥
< 19.01.14
siemenssimatic_ipc677d_firmware
𝑥
< 19.02.11
siemenssimatic_ipc827d_firmware
𝑥
< 19.02.11
siemenssimatic_ipc847d_firmware
𝑥
< 19.01.14
siemenssimatic_itp1000_firmware
𝑥
< 23.01.04
intelconverged_security_management_engine_firmware
11.0.0 ≤
𝑥
< 12.0.5
intelactive_management_technology_firmware
𝑥
< 12.0.5
intelmanageability_engine_firmware
9.0.0.0 ≤
𝑥
< 11.0
𝑥
= Vulnerable software versions