Lucene search

K
cveIntelCVE-2018-3682
HistoryJul 10, 2018 - 9:29 p.m.

CVE-2018-3682

2018-07-1021:29:01
CWE-269
intel
web.nvd.nist.gov
27
cve-2018-3682
intel server
compute modules
system
bmc firmware
smbus
unauthorized access
security vulnerability
nvd

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0

Percentile

12.6%

BMC Firmware in Intel server boards, compute modules, and systems potentially allow an attacker with administrative privileges to make unauthorized read\writes to the SMBUS.

Affected configurations

Nvd
Node
intelbmc_firmwareMatch-
AND
intelbbs2600bpbMatch-
OR
intelbbs2600bpqMatch-
OR
intelbbs2600bpsMatch-
OR
intelbbs2600stbMatch-
OR
intelbbs2600stqMatch-
OR
intelbbs7200apMatch-
OR
intelbbs7200aplMatch-
OR
inteldbs2600cw2rMatch-
OR
inteldbs2600cw2srMatch-
OR
inteldbs2600cwtrMatch-
OR
inteldbs2600cwtsrMatch-
OR
intelhns2600bpbMatch-
OR
intelhns2600bpb24Match-
OR
intelhns2600bpblcMatch-
OR
intelhns2600bpblc24Match-
OR
intelhns2600bpqMatch-
OR
intelhns2600bpq24Match-
OR
intelhns2600bpsMatch-
OR
intelhns2600bps24Match-
OR
intelhns2600kpfrMatch-
OR
intelhns2600kprMatch-
OR
intelhns2600tp24rMatch-
OR
intelhns2600tp24srMatch-
OR
intelhns2600tp24strMatch-
OR
intelhns2600tpfrMatch-
OR
intelhns2600tpnrMatch-
OR
intelhns2600tprMatch-
OR
intelhns7200apMatch-
OR
intelhns7200aplMatch-
OR
intelhns7200aprMatch-
OR
intelhns7200aprlMatch-
OR
intelr1208wftysMatch-
OR
intelr1208wt2gsrMatch-
OR
intelr1208wttgsrMatch-
OR
intelr1304wf0ysMatch-
OR
intelr1304wftysMatch-
OR
intelr1304wt2gsrMatch-
OR
intelr1304wttgsrMatch-
OR
intelr2208wf0zsMatch-
OR
intelr2208wfqzsMatch-
OR
intelr2208wftzsMatch-
OR
intelr2208wt2ysrMatch-
OR
intelr2208wttyc1rMatch-
OR
intelr2208wttysrMatch-
OR
intelr2224wfqzsMatch-
OR
intelr2224wftzsMatch-
OR
intelr2224wttysrMatch-
OR
intelr2308wftzsMatch-
OR
intelr2308wttysrMatch-
OR
intelr2312wf0npMatch-
OR
intelr2312wfqzsMatch-
OR
intelr2312wftzsMatch-
OR
intelr2312wttysrMatch-
OR
intels2600kpfrMatch-
OR
intels2600kprMatch-
OR
intels2600kptrMatch-
OR
intels2600stbMatch-
OR
intels2600stqMatch-
OR
intels2600tpfrMatch-
OR
intels2600tpnrMatch-
OR
intels2600tprMatch-
OR
intels2600tptrMatch-
OR
intels2600wfoMatch-
OR
intels2600wfqMatch-
OR
intels2600wftMatch-
OR
intels2600wt2rMatch-
OR
intels2600wttrMatch-
OR
intels2600wtts1rMatch-
OR
intels7200aprMatch-
VendorProductVersionCPE
intelbmc_firmware-cpe:2.3:o:intel:bmc_firmware:-:*:*:*:*:*:*:*
intelbbs2600bpb-cpe:2.3:h:intel:bbs2600bpb:-:*:*:*:*:*:*:*
intelbbs2600bpq-cpe:2.3:h:intel:bbs2600bpq:-:*:*:*:*:*:*:*
intelbbs2600bps-cpe:2.3:h:intel:bbs2600bps:-:*:*:*:*:*:*:*
intelbbs2600stb-cpe:2.3:h:intel:bbs2600stb:-:*:*:*:*:*:*:*
intelbbs2600stq-cpe:2.3:h:intel:bbs2600stq:-:*:*:*:*:*:*:*
intelbbs7200ap-cpe:2.3:h:intel:bbs7200ap:-:*:*:*:*:*:*:*
intelbbs7200apl-cpe:2.3:h:intel:bbs7200apl:-:*:*:*:*:*:*:*
inteldbs2600cw2r-cpe:2.3:h:intel:dbs2600cw2r:-:*:*:*:*:*:*:*
inteldbs2600cw2sr-cpe:2.3:h:intel:dbs2600cw2sr:-:*:*:*:*:*:*:*
Rows per page:
1-10 of 701

CNA Affected

[
  {
    "product": "Intel Server Boards, Compute Modules and Systems",
    "vendor": "Intel Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "BMC Equipped"
      }
    ]
  }
]

CVSS2

4.6

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:P/I:P/A:P

CVSS3

8.2

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

AI Score

8.1

Confidence

High

EPSS

0

Percentile

12.6%

Related for CVE-2018-3682