CVE-2018-3652

HIGHCVSS 7.6/10EPSS 0.36%

Last modified

CVE-2018-3652 is a high-severity vulnerability rated 7.6/10 on the CVSS scale. Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.

Description

Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.

Metrics

CVSS 3.1
7.6/10

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
0.36%

28.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
IntelXeon E31505m_v6
IntelXeon E31515m_v5
IntelXeon E31535m_v5
IntelXeon E31535m_v6
IntelXeon E31545m_v5
IntelXeon E31558l_v5
IntelXeon E31565l_v5
IntelXeon E31575m_v5
IntelXeon E31578l_v5
IntelXeon E31585_v5
IntelXeon E31585l_v5
IntelXeon E3 1220 V5All versions
IntelXeon E3 1220 V6All versions
IntelXeon E3 1225 V5All versions
IntelXeon E3 1225 V6All versions
IntelXeon E3 1230 V5All versions
IntelXeon E3 1230 V6All versions
IntelXeon E3 1235l V5All versions
IntelXeon E3 1240 V5All versions
IntelXeon E3 1240 V6All versions
IntelXeon E3 1240l V5All versions
IntelXeon E3 1245 V5All versions
IntelXeon E3 1245 V6All versions
IntelXeon E3 1260l V5All versions
IntelXeon E3 1268l V5All versions
IntelXeon E3 1270 V5All versions
IntelXeon E3 1270 V6All versions
IntelXeon E3 1275 V5All versions
IntelXeon E3 1275 V6All versions
IntelXeon E3 1280 V5All versions
IntelXeon E3 1280 V6All versions
IntelXeon E3 1285 V6All versions
IntelXeon E3 1501l V6All versions
IntelXeon E3 1501m V6All versions
IntelXeon E3 1505l V5All versions
IntelXeon E3 1505l V6All versions
IntelXeon E3 1505m V5All versions
IntelXeon Bronze 3104All versions
IntelXeon Bronze 3106All versions
IntelXeon Gold5115
IntelXeon Gold5118
IntelXeon Gold5119t
IntelXeon Gold5120
IntelXeon Gold5120t
IntelXeon Gold5122
IntelXeon Gold6126
IntelXeon Gold6126f
IntelXeon Gold6126t
IntelXeon Gold6128
IntelXeon Gold6130

Showing 50 of 164 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-3652?
Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.
How severe is CVE-2018-3652?
CVE-2018-3652 has a CVSS score of 7.6/10 (HIGH severity). The EPSS model estimates a 0.36% probability of exploitation in the next 30 days.
How do I fix CVE-2018-3652?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-3652?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST