7.2
CVSSv2

CVE-2018-12192

Published: 14/03/2019 Updated: 04/04/2019
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
CVSS v3 Base Score: 6.8 | Impact Score: 5.9 | Exploitability Score: 0.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Logic bug in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before version SPS_E5_04.00.04.393.0 may allow an unauthenticated user to potentially bypass MEBx authentication via physical access.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

intel server platform services firmware

intel converged security management engine firmware

Vendor Advisories

Potential security vulnerabilities have been identified with Intel® CSME, Server Platform Services, Trusted Execution Engine, and Intel® Active Management Technology that may allow users to potentially escalate privileges, disclose information or cause a denial of service ...
Potential security vulnerabilities have been identified with Intel® CSME, Server Platform Services, Trusted Execution Engine, and Intel® Active Management Technology that may allow users to potentially escalate privileges, disclose information or cause a denial of service ...