CVE Vulnerabilities

CVE-2018-3616

Published: Sep 12, 2018 | Modified: Nov 21, 2024
CVSS 3.x
5.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.

Affected Software

NameVendorStart VersionEnd Version
Converged_security_management_engine_firmwareIntel11.0.0 (including)12.0.5 (excluding)
Active_management_technology_firmwareIntel*12.0.5 (excluding)
Manageability_engine_firmwareIntel9.0.0.0 (including)11.0 (excluding)

References