Lucene search

K
lenovoLenovoLENOVO:PS500186-INTEL-CSME-SPS-AND-TXE-VULNERABILITIES-NOSID
HistoryOct 01, 2018 - 7:13 p.m.

Intel CSME / SPS and TXE Vulnerabilities - Lenovo Support NL

2018-10-0119:13:00
support.lenovo.com
10

EPSS

0.009

Percentile

83.1%

Lenovo Security Advisory: LEN-22810

Potential Impact: Elevation of privilege, information disclosure, denial of service

Severity: High

Scope of Impact: Industry-wide

CVE Identifier: CVE-2018-3655, CVE-2018-3657, CVE-2018-3658, CVE-2018-3659, CVE-2018-3616

Summary Description: Intel has disclosed multiple Converged Security and Management Engine (CSME) / Server Platform Services (SPS) and Trusted Execution Environment (TXE) vulnerabilities, allowing an attacker to potentially expose information stored by CSME, change CSME / SPS data or settings, execute code on CSME, and deny service via network access. Please see the Intel security advisories referenced below for details.

Mitigation Strategy for Customers (what you should do to protect yourself): All CSME / SPS and TXE fixes are rolled-up into firmware packages for each model. Intel recommends upgrading to the CSME or SPS firmware to the version (or newer) indicated for your model in the Product Impact section below.

Product Impact:

EPSS

0.009

Percentile

83.1%

Related for LENOVO:PS500186-INTEL-CSME-SPS-AND-TXE-VULNERABILITIES-NOSID