PT-2019-1665 · Intel · Intel Compute Modules+2
Published
2019-03-12
·
Updated
2019-10-03
·
CVE-2018-12204
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module (affected versions not specified)
Description
The issue is related to inadequate access control and improper memory initialization in the Platform Sample/Silicon Reference firmware. This could potentially allow a privileged user to escalate privileges via local access, or enable an attacker to execute arbitrary code.
Recommendations
For Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module, consider restricting local access to minimize the risk of exploitation until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Initialization
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Intel Compute Modules
Intel Server Boards
Intel Server Systems