PT-2018-1595 · Intel · Intel Csme+1
CVE-2018-3658
·
Publicado
2018-09-12
·
Atualizado
2023-08-17
CVSS v3.1
5.3
Média
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Intel CSME firmware versions prior to 12.0.5
Description
The issue is caused by multiple memory leaks in Intel Active Management Technology (AMT) in Intel Converged Security and Manageability Engine (CSME) firmware. This may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial of service via network access. The vulnerability can be exploited by a remote attacker, leading to a denial of service.
Recommendations
For Intel CSME firmware versions prior to 12.0.5, update to version 12.0.5 or later to resolve the issue. As a temporary workaround, consider restricting network access to Intel AMT to minimize the risk of exploitation.
Correção
Missing Release of Resource after Effective Lifetime
Improper Resource Release
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Intel Amt
Intel Csme