Lucene search

K
cveIntelCVE-2018-12166
HistoryJan 10, 2019 - 8:29 p.m.

CVE-2018-12166

2019-01-1020:29:00
CWE-20
intel
web.nvd.nist.gov
23
cve-2018-12166
intel
optane
ssd
firmware
write protection
denial of service
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

AI Score

4.4

Confidence

High

EPSS

0

Percentile

12.6%

Insufficient write protection in firmware for Intelยฎ Optaneโ„ข SSD DC P4800X before version E2010435 may allow a privileged user to potentially enable a denial of service via local access.

Affected configurations

Nvd
Node
inteloptane_ssd_dc_p4800x_firmwareRange<e2010435
AND
inteloptane_ssd_dc_p4800xMatch-
VendorProductVersionCPE
inteloptane_ssd_dc_p4800x_firmware*cpe:2.3:o:intel:optane_ssd_dc_p4800x_firmware:*:*:*:*:*:*:*:*
inteloptane_ssd_dc_p4800x-cpe:2.3:h:intel:optane_ssd_dc_p4800x:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Intel(R) Optane(TM) SSD DC P4800X",
    "vendor": "Intel Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "before version E2010435."
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

4.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H

AI Score

4.4

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2018-12166