CVE-2018-3616

Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc547e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pc547e:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_pc547g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc547g:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc627d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc627d:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc647d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647d:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc677d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc677d:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc827d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc827d:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc847d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847d:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:*

History

17 Aug 2023, 17:43

Type Values Removed Values Added
First Time Intel manageability Engine Firmware
Intel active Management Technology Firmware
CPE cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*

Information

Published : 2018-09-12 19:29

Updated : 2024-02-28 16:48


NVD link : CVE-2018-3616

Mitre link : CVE-2018-3616

CVE.ORG link : CVE-2018-3616


JSON object : View

Products Affected

intel

  • manageability_engine_firmware
  • converged_security_management_engine_firmware
  • active_management_technology_firmware

siemens

  • simatic_ipc827d
  • simatic_ipc547e_firmware
  • simatic_ipc627d
  • simatic_ipc847d
  • simatic_field_pg_m5_firmware
  • simatic_ipc647d
  • simatic_ipc427e
  • simatic_field_pg_m5
  • simatic_itp1000
  • simatic_ipc477e
  • simatic_pc547g_firmware
  • simatic_ipc627d_firmware
  • simatic_itp1000_firmware
  • simatic_ipc427e_firmware
  • simatic_ipc647d_firmware
  • simatic_pc547e
  • simatic_ipc677d_firmware
  • simatic_ipc827d_firmware
  • simatic_ipc477e_firmware
  • simatic_ipc547g
  • simatic_ipc847d_firmware
  • simatic_ipc677d