CVE-2018-12169
Last modified
CVE-2018-12169 is a vulnerability of currently unknown severity. Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.. EPSS estimates a 0.55% chance of exploitation in the next 30 days.
Description
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Intel | Core I3 | 4000m |
| Intel | Core I3 | 4005u |
| Intel | Core I3 | 4010u |
| Intel | Core I3 | 4010y |
| Intel | Core I3 | 4012y |
| Intel | Core I3 | 4020y |
| Intel | Core I3 | 4025u |
| Intel | Core I3 | 4030u |
| Intel | Core I3 | 4030y |
| Intel | Core I3 | 4100e |
| Intel | Core I3 | 4100m |
| Intel | Core I3 | 4100u |
| Intel | Core I3 | 4102e |
| Intel | Core I3 | 4110e |
| Intel | Core I3 | 4110m |
| Intel | Core I3 | 4112e |
| Intel | Core I3 | 4120u |
| Intel | Core I3 | 4130 |
| Intel | Core I3 | 4130t |
| Intel | Core I3 | 4150 |
| Intel | Core I3 | 4150t |
| Intel | Core I3 | 4158u |
| Intel | Core I3 | 4160 |
| Intel | Core I3 | 4160t |
| Intel | Core I3 | 4170 |
| Intel | Core I3 | 4170t |
| Intel | Core I3 | 4330 |
| Intel | Core I3 | 4330t |
| Intel | Core I3 | 4330te |
| Intel | Core I3 | 4340 |
| Intel | Core I3 | 4340te |
| Intel | Core I3 | 4350 |
| Intel | Core I3 | 4350t |
| Intel | Core I3 | 4360 |
| Intel | Core I3 | 4360t |
| Intel | Core I3 | 4370 |
| Intel | Core I3 | 4370t |
| Intel | Core I3 | 5005u |
| Intel | Core I3 | 5010u |
| Intel | Core I3 | 5015u |
| Intel | Core I3 | 5020u |
| Intel | Core I3 | 5157u |
| Intel | Core I3 | 6006u |
| Intel | Core I3 | 6098p |
| Intel | Core I3 | 6100 |
| Intel | Core I3 | 6100e |
| Intel | Core I3 | 6100h |
| Intel | Core I3 | 6100t |
| Intel | Core I3 | 6100te |
| Intel | Core I3 | 6100u |
Showing 50 of 345 affected configurations. See NVD for the full list.
References
- http://www.securityfocus.com/bid/105387Third Party Advisory, VDB Entry
- https://support.lenovo.com/us/en/solutions/LEN-20527Mitigation, Third Party Advisory
- http://www.securityfocus.com/bid/105387Third Party Advisory, VDB Entry
- https://support.lenovo.com/us/en/solutions/LEN-20527Mitigation, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-12169?
How severe is CVE-2018-12169?
How do I fix CVE-2018-12169?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-12163A DLL injection vulnerability in the Intel IoT Developers Ki…
- CVE-2018-12164Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-12165Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-12166Insufficient write protection in firmware for Intel(R) Optan…
- CVE-2018-12167Firmware update routine in bootloader for Intel(R) Optane(TM…
- CVE-2018-12168Privilege escalation in file permissions in Intel Computing …
- CVE-2018-1217Avamar Installation Manager in Dell EMC Avamar Server 7.3.1,…
- CVE-2018-12170Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2018-12171Privilege escalation in Intel Baseboard Management Controlle…
- CVE-2018-12172Improper password hashing in firmware in Intel Server Board …
- CVE-2018-12173Insufficient access protection in firmware in Intel Server B…
- CVE-2018-12174Heap overflow in Intel Trace Analyzer 2018 in Intel Parallel…
Are you affected by CVE-2018-12169?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
