PT-2019-1665 · Intel · Intel Compute Modules+2

Published

2019-03-12

·

Updated

2019-10-03

·

CVE-2018-12204

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module (affected versions not specified)
Description The issue is related to inadequate access control and improper memory initialization in the Platform Sample/Silicon Reference firmware. This could potentially allow a privileged user to escalate privileges via local access, or enable an attacker to execute arbitrary code.
Recommendations For Intel(R) Server Board, Intel(R) Server System and Intel(R) Compute Module, consider restricting local access to minimize the risk of exploitation until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Initialization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-01213
CVE-2018-12204

Affected Products

Intel Compute Modules
Intel Server Boards
Intel Server Systems