Lucene search

K
cveIntelCVE-2018-12180
HistoryMar 27, 2019 - 8:29 p.m.

CVE-2018-12180

2019-03-2720:29:03
CWE-787
intel
web.nvd.nist.gov
118
cve-2018-12180
buffer overflow
blockio service
edk ii
unauthenticated user
privilege escalation
information disclosure
denial of service
network access

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.014

Percentile

86.7%

Buffer overflow in BlockIo service for EDK II may allow an unauthenticated user to potentially enable escalation of privilege, information disclosure and/or denial of service via network access.

Affected configurations

Nvd
Vulners
Node
tianocoreedk_iiMatch-
Node
opensuseleapMatch15.0
VendorProductVersionCPE
tianocoreedk_ii-cpe:2.3:a:tianocore:edk_ii:-:*:*:*:*:*:*:*
opensuseleap15.0cpe:2.3:o:opensuse:leap:15.0:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Extensible Firmware Interface Development Kit (EDK II)",
    "vendor": "Extensible Firmware Interface Development Kit (EDK II)",
    "versions": [
      {
        "status": "affected",
        "version": "N/A"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.014

Percentile

86.7%