2023-04-24 12:24:31 +02:00
{
"id" : "CVE-2018-3616" ,
"sourceIdentifier" : "secure@intel.com" ,
"published" : "2018-09-12T19:29:02.403" ,
2023-08-17 18:00:37 +00:00
"lastModified" : "2023-08-17T17:43:53.193" ,
2023-04-24 12:24:31 +02:00
"vulnStatus" : "Analyzed" ,
"descriptions" : [
{
"lang" : "en" ,
"value" : "Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network."
} ,
{
"lang" : "es" ,
"value" : "Vulnerabilidad de canal lateral estilo Bleichenbacher en la implementaci\u00f3n TLS en Intel Active Management Technology en versiones anteriores a la 12.0.5 podr\u00eda permitir que un usuario sin autenticar obtenga la clave de sesi\u00f3n TLS por red."
}
] ,
"metrics" : {
"cvssMetricV31" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N" ,
"attackVector" : "NETWORK" ,
"attackComplexity" : "HIGH" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "NONE" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 5.9 ,
"baseSeverity" : "MEDIUM"
} ,
"exploitabilityScore" : 2.2 ,
"impactScore" : 3.6
}
] ,
"cvssMetricV2" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"cvssData" : {
"version" : "2.0" ,
"vectorString" : "AV:N/AC:M/Au:N/C:P/I:N/A:N" ,
"accessVector" : "NETWORK" ,
"accessComplexity" : "MEDIUM" ,
"authentication" : "NONE" ,
"confidentialityImpact" : "PARTIAL" ,
"integrityImpact" : "NONE" ,
"availabilityImpact" : "NONE" ,
"baseScore" : 4.3
} ,
"baseSeverity" : "MEDIUM" ,
"exploitabilityScore" : 8.6 ,
"impactScore" : 2.9 ,
"acInsufInfo" : false ,
"obtainAllPrivilege" : false ,
"obtainUserPrivilege" : false ,
"obtainOtherPrivilege" : false ,
"userInteractionRequired" : false
}
]
} ,
"weaknesses" : [
{
"source" : "nvd@nist.gov" ,
"type" : "Primary" ,
"description" : [
{
"lang" : "en" ,
"value" : "NVD-CWE-noinfo"
}
]
}
] ,
"configurations" : [
{
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:a:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*" ,
2023-08-17 18:00:37 +00:00
"versionStartIncluding" : "11.0.0" ,
"versionEndExcluding" : "12.0.5" ,
"matchCriteriaId" : "C23AFAB4-B286-4FD6-ABC3-86B2881E271C"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*" ,
2023-04-24 12:24:31 +02:00
"versionEndExcluding" : "12.0.5" ,
2023-08-17 18:00:37 +00:00
"matchCriteriaId" : "D5FAD938-027A-406F-9E7C-1BFD992839F4"
} ,
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*" ,
"versionStartIncluding" : "9.0.0.0" ,
"versionEndExcluding" : "11.0" ,
"matchCriteriaId" : "63591E72-6038-4417-BA10-54180507AF0F"
2023-04-24 12:24:31 +02:00
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "22.01.06" ,
"matchCriteriaId" : "503E551C-FC5F-4ABC-8DEA-E360701F0B33"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "506DEE00-30D2-4E29-9645-757EB8778C0F"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "21.01.09" ,
"matchCriteriaId" : "33F546AF-8F80-4E0A-9B92-86E3A1F931C0"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "A40D0CDB-7BE6-491F-B730-3B4E10CA159A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "21.01.09" ,
"matchCriteriaId" : "6B5B6E6B-16A0-4236-AABE-82385B53EC78"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "FDF9D4C3-1892-48FA-95B4-835B636A4005"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_ipc547e_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "r1.30.0" ,
"matchCriteriaId" : "D476D093-4A97-499C-B40D-7A301BC9AA2E"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_pc547e:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "F6A757F1-E478-4A3D-8D5F-C996E176A11A"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_pc547g_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "r1.23.0" ,
"matchCriteriaId" : "30F129DB-51AC-4F40-A0D1-AB5CF90D9C2D"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_ipc547g:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "9EB339B5-602F-4AB5-9998-465FDC6ABD6C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_ipc627d_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "19.02.11" ,
"matchCriteriaId" : "790D244A-AC3D-4BBC-9139-A90048FD375A"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_ipc627d:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "509AD120-3465-4C00-AAB3-B6F6ED708B51"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_ipc647d_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "19.01.14" ,
"matchCriteriaId" : "0C046182-BB33-41D0-B041-1566B8041917"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_ipc647d:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D0EF28FB-BAB3-4710-9D25-25F67ACADC60"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_ipc677d_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "19.02.11" ,
"matchCriteriaId" : "8DE74300-E061-452E-AD1D-6DD7C2C62729"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_ipc677d:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "057D9947-CE4A-4B4C-B721-4B29FB71350C"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_ipc827d_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "19.02.11" ,
"matchCriteriaId" : "BE4A7C13-6F81-4629-9C28-9202028634AE"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_ipc827d:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "E6D87239-40C1-4038-B734-D77AC4DDD571"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_ipc847d_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "19.01.14" ,
"matchCriteriaId" : "93485235-481B-4BAF-BB7A-81BB5AA1BC53"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_ipc847d:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "D8F37D88-E086-4060-8420-BD0F8D8FF580"
}
]
}
]
} ,
{
"operator" : "AND" ,
"nodes" : [
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : true ,
"criteria" : "cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:*" ,
"versionEndExcluding" : "23.01.04" ,
"matchCriteriaId" : "AD949046-46E5-48C9-883B-92F04926E8BC"
}
]
} ,
{
"operator" : "OR" ,
"negate" : false ,
"cpeMatch" : [
{
"vulnerable" : false ,
"criteria" : "cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:*" ,
"matchCriteriaId" : "187C6D51-5B86-484D-AE0F-26D1C9465580"
}
]
}
]
}
] ,
"references" : [
{
"url" : "http://www.securityfocus.com/bid/106996" ,
"source" : "secure@intel.com" ,
"tags" : [
"Third Party Advisory" ,
"VDB Entry"
]
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/pdf/ssa-377318.pdf" ,
"source" : "secure@intel.com" ,
"tags" : [
"Patch" ,
"Third Party Advisory"
]
} ,
{
"url" : "https://ics-cert.us-cert.gov/advisories/ICSA-19-043-05" ,
"source" : "secure@intel.com" ,
"tags" : [
"Third Party Advisory" ,
"US Government Resource"
]
} ,
{
"url" : "https://security.netapp.com/advisory/ntap-20180924-0003/" ,
"source" : "secure@intel.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03876en_us" ,
"source" : "secure@intel.com" ,
"tags" : [
"Third Party Advisory"
]
} ,
{
"url" : "https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00141.html" ,
"source" : "secure@intel.com" ,
"tags" : [
"Vendor Advisory"
]
}
]
}