CVE-2018-12188
Estado: ModificadaMedia (4.6)—
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
- Puntuación base: 4.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-20
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2018-12188",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.1,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
],
"cvssMetricV30": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.0",
"baseScore": 4.6,
"attackVector": "PHYSICAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 0.9
}
]
},
"affected": [
{
"source": "secure@intel.com",
"affectedData": [
{
"vendor": "Intel Corporation",
"product": "Intel(R) CSME, Server Platform Services, Trusted Execution Engine and Intel(R) Active Management Technology",
"versions": [
{
"status": "affected",
"version": "Multiple versions."
}
]
}
]
}
],
"published": "2019-03-14T20:29:00.350",
"references": [
{
"url": "https://security.netapp.com/advisory/ntap-20190318-0001/",
"source": "secure@intel.com"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.html",
"tags": [
"Vendor Advisory"
],
"source": "secure@intel.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20190318-0001/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.intel.com/content/www/us/en/security-center/advisory/INTEL-SA-00185.html",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-20"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access."
},
{
"lang": "es",
"value": "Validación de entradas incorrecta en Intel CSME, en versiones anteriores a las 11.8.60, 11.11.60, 11.22.60 o 12.0.20; o Intel TXE, en versiones anteriores a la 3.1.60 o 4.0.10, podría permitir que un usuario no autenticado pueda modificar datos mediante acceso físico."
}
],
"lastModified": "2026-06-17T01:37:17.330",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "89FAC2D9-E921-4F45-B786-0902B310C2A3",
"versionEndExcluding": "11.8.60",
"versionStartIncluding": "11.0"
},
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EB85F0E9-95F9-452C-AAAF-0C8CCCE76C59",
"versionEndExcluding": "11.11.60",
"versionStartIncluding": "11.10"
},
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3A44D8E6-445C-475D-BB1A-75C03AEE940B",
"versionEndExcluding": "11.22.60",
"versionStartIncluding": "11.20"
},
{
"criteria": "cpe:2.3:o:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91671FB7-F021-4781-9CBD-E7B66727B747",
"versionEndExcluding": "12.0.20",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3029FF22-3BD0-41A7-BBF9-E6183DF2BD31",
"versionEndExcluding": "3.1.60",
"versionStartIncluding": "3.0"
},
{
"criteria": "cpe:2.3:o:intel:trusted_execution_engine_firmware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "916A348F-144A-4A81-B93F-D3422A662D09",
"versionEndExcluding": "4.0.10",
"versionStartIncluding": "4.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secure@intel.com"
}