Vulnerability Name:

CVE-2018-12171 (CCN-150107)

Assigned:2018-09-11
Published:2018-09-11
Updated:2019-10-03
Summary:Privilege escalation in Intel Baseboard Management Controller (BMC) firmware before version 1.43.91f76955 may allow an unprivileged user to potentially execute arbitrary code or perform denial of service over the network.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
8.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H)
7.2 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
7.1 High (CCN CVSS v2 Vector: AV:N/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2018-12171

Source: XF
Type: UNKNOWN
intel-cve201812171-priv-esc(150107)

Source: CCN
Type: INTEL-SA-00149
Intel Baseboard Management Controller (BMC) firmware Advisory

Source: CONFIRM
Type: Vendor Advisory
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00149.html

Vulnerable Configuration:Configuration 1:
  • cpe:/o:intel:bmc_firmware:*:*:*:*:*:*:*:* (Version < 1.43.91f76955)
  • AND
  • cpe:/h:intel:bbs2600bpb:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:bbs2600bpq:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:bbs2600bps:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:bbs2600stb:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:bbs2600stq:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:hns2600bpb:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:hns2600bpb24:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:hns2600bpblc:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:hns2600bpblc24:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:hns2600bpq:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:hns2600bpq24:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:hns2600bps:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:hns2600bps24:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r1208wftys:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r1304wf0ys:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r1304wftys:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2208wf0zs:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2208wfqzs:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2208wftzs:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2224wfqzs:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2224wftzs:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2308wftzs:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2312wf0np:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2312wfqzs:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:r2312wftzs:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:s2600stb:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:s2600stq:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:s2600wfo:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:s2600wfq:-:*:*:*:*:*:*:*
  • OR cpe:/h:intel:s2600wft:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    intel bmc firmware *
    intel bbs2600bpb -
    intel bbs2600bpq -
    intel bbs2600bps -
    intel bbs2600stb -
    intel bbs2600stq -
    intel hns2600bpb -
    intel hns2600bpb24 -
    intel hns2600bpblc -
    intel hns2600bpblc24 -
    intel hns2600bpq -
    intel hns2600bpq24 -
    intel hns2600bps -
    intel hns2600bps24 -
    intel r1208wftys -
    intel r1304wf0ys -
    intel r1304wftys -
    intel r2208wf0zs -
    intel r2208wfqzs -
    intel r2208wftzs -
    intel r2224wfqzs -
    intel r2224wftzs -
    intel r2308wftzs -
    intel r2312wf0np -
    intel r2312wfqzs -
    intel r2312wftzs -
    intel s2600stb -
    intel s2600stq -
    intel s2600wfo -
    intel s2600wfq -
    intel s2600wft -