« Volver al listado

CVE-2018-3624

Estado: ModificadaAlta (8.3)—

Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2018-3624",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5.4,
          "accessVector": "ADJACENT_NETWORK",
          "vectorString": "AV:A/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 5.5,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 8.3,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 6,
        "exploitabilityScore": 1.6
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "Intel Corporation",
          "product": "Intel XMM71xx, Intel XMM72xx, Intel XMM73xx, Intel XMM74xx, Sofia 3G, Sofia 3G-R, and Sofia 3G-RW",
          "versions": [
            {
              "status": "affected",
              "version": "All"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-04-05T16:29:00.393",
  "references": [
    {
      "url": "http://www.securityfocus.com/bid/103968",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-114-02",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00116&languageid=en-fr",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "http://www.securityfocus.com/bid/103968",
      "tags": [
        "Third Party Advisory",
        "VDB Entry"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://ics-cert.us-cert.gov/advisories/ICSA-18-114-02",
      "tags": [
        "Third Party Advisory",
        "US Government Resource"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00116&languageid=en-fr",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-119"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network."
    },
    {
      "lang": "es",
      "value": "Desbordamiento de búfer en el módulo de procesamiento ETWS en Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx y Sofia 3G/R permite que atacantes remotos ejecuten código arbitrario mediante una red adyacente."
    }
  ],
  "lastModified": "2026-06-17T01:57:34.653",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:intel:2g_modem_firmware:-:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "066AC9C9-A535-41B3-B1D8-A032B378B6C5"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:intel:sofia_3g:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "0E5D7652-5616-4CE2-9F2A-12A290ECB2AA"
            },
            {
              "criteria": "cpe:2.3:h:intel:sofia_3g-r:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "00A7C203-FCEE-4A04-B0EF-56B17FACF97B"
            },
            {
              "criteria": "cpe:2.3:h:intel:sofia_3g-r_w:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "4CBED0FB-8114-421F-BD1A-5CEB9BB8C3A7"
            },
            {
              "criteria": "cpe:2.3:h:intel:xmm71xx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "1F3E5FCF-8D35-460F-B5DE-20B2B5F84436"
            },
            {
              "criteria": "cpe:2.3:h:intel:xmm72xx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "5404667A-6C3D-45B0-B8FD-F19384216E63"
            },
            {
              "criteria": "cpe:2.3:h:intel:xmm73xx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "30BC780E-C105-43CA-A5AD-E529B9624BE7"
            },
            {
              "criteria": "cpe:2.3:h:intel:xmm74xx:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "2621B46F-8A61-4A5F-961F-6EB225F49FB1"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secure@intel.com"
}