CVE-2018-12169 - CVE House
Back to Database
Status published High CVE-2018-12169

Platform sample code firmware in 4th Generation Intel Core Processor,...

Vulnerability Description

Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-12169

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

core i3, core i5, core i7, core i9, thinkpad 11e, thinkpad e480, thinkpad e580, thinkpad l380, thinkpad l380 yoga, thinkpad l480, thinkpad l580, thinkpad p51, thinkpad p51s, thinkpad p52, thinkpad p52s, thinkpad p71, thinkpad p72, thinkpad t25, thinkpad t470, thinkpad t470p, thinkpad t470s, thinkpad t480, thinkpad t480s, thinkpad t570, thinkpad t580, thinkpad x1 carbon, thinkpad x1 tablet, thinkpad x1 yoga, thinkpad x270, thinkpad x280, thinkpad x380 yoga, thinkpad yoga 370
Vulnerable Versions:
4000m, 4005u, 4010u, 4010y, 4012y, 4020y, 4025u, 4030u, 4030y, 4100e, 4100m, 4100u, 4102e, 4110e, 4110m, 4112e, 4120u, 4130, 4130t, 4150, 4150t, 4158u, 4160, 4160t, 4170, 4170t, 4330, 4330t, 4330te, 4340, 4340te, 4350, 4350t, 4360, 4360t, 4370, 4370t, 5005u, 5010u, 5015u, 5020u, 5157u, 6006u, 6098p, 6100, 6100e, 6100h, 6100t, 6100te, 6100u, 6102e, 6157u, 6167u, 6300, 6300t, 6320, 7020u, 7100, 7100e, 7100h, 7100t, 7100u, 7101e, 7101te, 7102e, 7130u, 7167u, 7300, 7300t, 7320, 7350k, 8100, 8100h, 8100t, 8109u, 8130u, 8145u, 8300, 8300t, 8350k, 7y54, 7y57, 4200h, 4200m, 4200u, 4200y, 4202y, 4210h, 4210m, 4210u, 4210y, 4220y, 4250u, 4258u, 4260u, 4278u, 4288u, 4300m, 4300u, 4300y, 4302y, 4308u, 4310m, 4310u, 4330m, 4340m, 4350u, 4360u, 4400e, 4402e, 4402ec, 4410e, 4422e, 4430, 4430s, 4440, 4440s, 4460, 4460s, 4460t, 4570, 4570r, 4570s, 4570t, 4570te, 4590, 4590s, 4590t, 4670, 4670k, 4670r, 4670s, 4670t, 4690k, 4690s, 4690t, 5200u, 5250u, 5257u, 5287u, 5300u, 5350h, 5350u, 5575r, 5675c, 5675r, 6200u, 6260u, 6267u, 6287u, 6300hq, 6300u, 6350hq, 6360u, 6400, 6400t, 6402p, 6440eq, 6440hq, 6442eq, 6500, 6500t, 6500te, 6585r, 6600, 6600k, 6600t, 6685r, 7200u, 7260u, 7267u, 7287u, 7300hq, 7300u, 7360u, 7400, 7400t, 7440eq, 7440hq, 7442eq, 7500, 7500t, 7600, 7600k, 7600t, 8200y, 8250u, 8259u, 8265u, 8269u, 8300h, 8305g, 8350u, 8400, 8400b, 8400h, 8400t, 8500, 8500b, 8500t, 8600, 8600k, 8600t, 7y75, 4500u, 4510u, 4550u, 4558u, 4578u, 4600m, 4600u, 4610m, 4610y, 4650u, 4700ec, 4700eq, 4700hq, 4700mq, 4702ec, 4702hq, 4702mq, 4710hq, 4710mq, 4712hq, 4712mq, 4720hq, 4722hq, 4750hq, 4760hq, 4765t, 4770, 4770hq, 4770k, 4770r, 4770s, 4770t, 4770te, 4771, 4785t, 4790, 4790k, 4790s, 4790t, 4800mq, 4810mq, 4850hq, 4860hq, 4870hq, 4900mq, 4910mq, 4950hq, 4960hq, 4980hq, 5500u, 5550u, 5557u, 5600u, 5650u, 5700eq, 5700hq, 5750hq, 5775c, 5775r, 5820k, 5850eq, 5850hq, 5950hq, 6500u, 6560u, 6567u, 6600u, 6650u, 6660u, 6700, 6700hq, 6700k, 6700t, 6700te, 6770hq, 6785r, 6820eq, 6820hk, 6820hq, 6822eq, 6870hq, 6920hq, 6970hq, 7500u, 7560u, 7567u, 7600u, 7660u, 7700, 7700hq, 7700k, 7700t, 7820eq, 7820hk, 7820hq, 7920hq, 8086k, 8500y, 8550u, 8559u, 8565u, 8650u, 8700, 8700b, 8700k, 8700t, 8705g, 8706g, 8709g, 8750h, 8809g, 8850h, 8950hk

Timeline

Official Publish: September 21st, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.