Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.
Metrics
No CVSS v4.0
Attack Vector Physical
Attack Complexity Low
Privileges Required None
Scope Changed
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction None
No CVSS v3.0
Access Vector Local
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.00145.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Intel
Subscribe
|
Atom C
Subscribe
Xeon
Subscribe
Xeon Bronze 3104
Subscribe
Xeon Bronze 3106
Subscribe
Xeon E3
Subscribe
Xeon E3 1220 V5
Subscribe
Xeon E3 1220 V6
Subscribe
Xeon E3 1225 V5
Subscribe
Xeon E3 1225 V6
Subscribe
Xeon E3 1230 V5
Subscribe
Xeon E3 1230 V6
Subscribe
Xeon E3 1235l V5
Subscribe
Xeon E3 1240 V5
Subscribe
Xeon E3 1240 V6
Subscribe
Xeon E3 1240l V5
Subscribe
Xeon E3 1245 V5
Subscribe
Xeon E3 1245 V6
Subscribe
Xeon E3 1260l V5
Subscribe
Xeon E3 1268l V5
Subscribe
Xeon E3 1270 V5
Subscribe
Xeon E3 1270 V6
Subscribe
Xeon E3 1275 V5
Subscribe
Xeon E3 1275 V6
Subscribe
Xeon E3 1280 V5
Subscribe
Xeon E3 1280 V6
Subscribe
Xeon E3 1285 V6
Subscribe
Xeon E3 1501l V6
Subscribe
Xeon E3 1501m V6
Subscribe
Xeon E3 1505l V5
Subscribe
Xeon E3 1505l V6
Subscribe
Xeon E3 1505m V5
Subscribe
Xeon Gold
Subscribe
Xeon Platinum
Subscribe
Xeon Silver
Subscribe
|
Configuration 1 [-]
|
Configuration 2 [-]
|
Configuration 3 [-]
|
Configuration 4 [-]
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-15506 | Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: intel
Published:
Updated: 2024-08-05T04:50:30.453Z
Reserved: 2017-12-28T00:00:00
Link: CVE-2018-3652
No data.
Status : Modified
Published: 2018-07-10T21:29:00.983
Modified: 2024-11-21T04:05:50.563
Link: CVE-2018-3652
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD