CVE-2018-3652

HIGH

Intel Xeon E3 5th-6th Gen - Exposure of Sensitive Information via DCI Debug Interface

Title source: llm
STIX 2.1

Description

Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20180802-0001/

Scores

CVSS v3 7.6
EPSS 0.0014
EPSS Percentile 34.4%
Attack Vector PHYSICAL
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Details

CWE
CWE-200
Status published
Products (50)
intel/atom_c c2308
intel/atom_c c2316
intel/atom_c c2338
intel/atom_c c2350
intel/atom_c c2358
intel/atom_c c2508
intel/atom_c c2516
intel/atom_c c2518
intel/atom_c c2530
intel/atom_c c2538
... and 40 more
Published Jul 10, 2018
Tracked Since Feb 18, 2026