Power Management Firmware Vulnerability in Intel Converged Security and Management Engine
CVE-2018-3643 
8.2HIGH
Key Information:
- Vendor
- Intel
- Vendor
- CVE Published:
- 12 September 2018
What is CVE-2018-3643?
A vulnerability exists in the Power Management Controller firmware associated with specific versions of Intel's Converged Security and Management Engine (CSME) and Server Platform Services. An attacker with administrative access may exploit this vulnerability to reveal sensitive platform secrets or potentially execute arbitrary code on the target system. This issue highlights the need for timely firmware updates to mitigate risks associated with unauthorized access and ensure system integrity.
Affected Version(s)
Intel(R) Converged Security and Management Engine (CSME) and Intel(R) Server Platform Services firmware CSME versions before 12.0.6 or Server Platform Services firmware before version 4.x.04.