Insufficient Input Validation in Intel's CSME and TXE Products
CVE-2018-12188
4.6MEDIUM
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 14 March 2019
Summary
Insufficient input validation in Intel CSME and TXE products could allow an unauthenticated user with physical access to manipulate critical data, posing a significant security risk. This vulnerability affects multiple versions of these products, highlighting the need for prompt updates to mitigate such threats. Users should take immediate action to secure their environments by upgrading to the latest versions as outlined in Intel's security advisories.
Affected Version(s)
Intel(R) CSME, Server Platform Services, Trusted Execution Engine and Intel(R) Active Management Technology Multiple versions.
References
CVSS V3.1
Score:
4.6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Physical
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved