Back to Database
Status published
High
CVE-2018-3612
Intel NUC kits with insufficient input validation in system firmware,...
Vulnerability Description
Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-3612
Credits & Attribution
No credits recorded in the NVD database.
More from intel
View All →CVE-2022-32293
In ConnMan through 1.41, a man-in-the-middle attack against a WISPR...
High
8.1
CVE-2022-32292
In ConnMan through 1.41, remote attackers able to send HTTP...
Critical
9.8
CVE-2022-23098
An issue was discovered in the DNS proxy in Connman...
High
7.5
CVE-2022-23097
An issue was discovered in the DNS proxy in Connman...
Critical
9.1
CVE-2022-23096
An issue was discovered in the DNS proxy in Connman...
Unknown
0
Affected Vendor
intel
View all reports →Affected Software
bios, ayaplcel.86a, bnkbl357.86a, ccsklm30.86a, ccsklm5v.86a, dnkbli30.86a, dnkbli5v.86a, dnkbli7v.86a, fybyt10h.86a, gkaplcpx.86a, kyskli70.86a, mkkbli5v.86a, mkkbly35.86a, mybdwi30.86a, mybdwi5v.86a, rybdwi35.86a, syskli35.86a, tybyt10h.86a
Vulnerable Versions:
ayaplcel.86a, bnkbl357.86a, ccsklm5v.86a, ccsklm30.86a, dnkbli5v.86a, dnkbli7v.86a, dnkbli30.86a, fybyt10h.86a, gkaplcpx.86a, kyskli70.86a, mkkbli5v.86a, mkkbly35.86a, mybdwi5v.86a, mybdwi30.86a, rybdwi35.86a, syskli35.86a, tybyt10h.86a
Timeline
Official Publish:
May 10th, 2018
Last Modified:
August 5th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.