CVE-2018-3628

HIGH

Intel Active Management Technology Firmware 3.0-11.22.70 - Buffer Overflow in HTTP Handler

Title source: llm
STIX 2.1

Description

Buffer overflow in HTTP handler in Intel Active Management Technology in Intel Converged Security Manageability Engine Firmware 3.x, 4.x, 5.x, 6.x, 7.x, 8.x, 9.x, 10.x, and 11.x may allow an attacker to execute arbitrary code via the same subnet.

References (4)

Core 4
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1041362
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190327-0001/

Scores

CVSS v3 8.8
EPSS 0.0040
EPSS Percentile 61.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
intel/active_management_technology_firmware 3.0 - 11.22.70
Published Jul 10, 2018
Tracked Since Feb 18, 2026