CVE & CISA-KEV Catalog

CVE-2018-3658

MEDIUMEPSS 87th pctl
5.3
CVSS v3
NVD

Description

Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access.

How to fix

Remediation Available
active management technology firmwareNVD
Affected:< 12.0.5Fixed in:12.0.5CVE-2018-3658derived from NVD
converged security management engine firmwareNVD
Affected:>= 11.0.0, < 12.0.5Fixed in:12.0.5CVE-2018-3658derived from NVD
manageability engine firmwareNVD
Affected:>= 9.0.0.0, < 11.0Fixed in:11.0CVE-2018-3658derived from NVD
simatic field pg m5 firmwareNVD
Affected:< 22.01.06Fixed in:22.01.06CVE-2018-3658derived from NVD
simatic ipc427e firmwareNVD
Affected:< 21.01.09Fixed in:21.01.09CVE-2018-3658derived from NVD
simatic ipc477e firmwareNVD
Affected:< 21.01.09Fixed in:21.01.09CVE-2018-3658derived from NVD
simatic ipc547e firmwareNVD
Affected:< r1.30.0Fixed in:r1.30.0CVE-2018-3658derived from NVD
simatic ipc627d firmwareNVD
Affected:< 19.02.11Fixed in:19.02.11CVE-2018-3658derived from NVD
simatic ipc647d firmwareNVD
Affected:< 19.01.14Fixed in:19.01.14CVE-2018-3658derived from NVD
simatic ipc677d firmwareNVD
Affected:< 19.02.11Fixed in:19.02.11CVE-2018-3658derived from NVD
simatic ipc827d firmwareNVD
Affected:< 19.02.11Fixed in:19.02.11CVE-2018-3658derived from NVD
simatic ipc847d firmwareNVD
Affected:< 19.01.14Fixed in:19.01.14CVE-2018-3658derived from NVD
simatic itp1000 firmwareNVD
Affected:< 23.01.04Fixed in:23.01.04CVE-2018-3658derived from NVD
simatic pc547g firmwareNVD
Affected:< r1.23.0Fixed in:r1.23.0CVE-2018-3658derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityNone
IntegrityNone
AvailabilityLow

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Exploit Intelligence

3.30%probability of exploitation in 30 days
87thpercentile

Elevated risk: more likely to be exploited than 87% of all known CVEs.

References

Embed a live status badge for CVE-2018-3658
CVE-2018-3658 severity badge

Markdown

[![CVE-2018-3658](https://tridentstack.com/cve/badge/CVE-2018-3658.svg)](https://tridentstack.com/cve/CVE-2018-3658)

HTML

<a href="https://tridentstack.com/cve/CVE-2018-3658"><img src="https://tridentstack.com/cve/badge/CVE-2018-3658.svg" alt="CVE-2018-3658"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.