ID

VAR-201807-1640


CVE

CVE-2018-3682


TITLE

BMC Firmware vulnerabilities related to authorization, authority, and access control

Trust: 0.8

sources: JVNDB: JVNDB-2018-008010

DESCRIPTION

BMC Firmware in Intel server boards, compute modules, and systems potentially allow an attacker with administrative privileges to make unauthorized read\writes to the SMBUS. BMC Firmware contains vulnerabilities related to authorization, permissions, and access control.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. Intel ServerBoard, ComputeModule, and ServerSystem are products of Intel Corporation of the United States. IntelServerBoard is a server motherboard. ComputeModule is a computing module. ServerSystem is a server array card. A security vulnerability exists in the BMC firmware in IntelServerBoard, IntelComputeModule, and IntelServerSystem. An attacker could exploit this vulnerability to perform write and read operations on SMBUS

Trust: 2.25

sources: NVD: CVE-2018-3682 // JVNDB: JVNDB-2018-008010 // CNVD: CNVD-2018-15554 // VULHUB: VHN-133713

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-15554

AFFECTED PRODUCTS

vendor:intelmodel:bmcscope:eqversion: -

Trust: 1.6

vendor:intelmodel:bmcscope: - version: -

Trust: 0.8

vendor:intelmodel:intel\302\256 server boardscope: - version: -

Trust: 0.6

vendor:intelmodel:intel\302\256 compute modulescope: - version: -

Trust: 0.6

vendor:intelmodel:intel\302\256 server systemscope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2018-15554 // JVNDB: JVNDB-2018-008010 // CNNVD: CNNVD-201807-889 // NVD: CVE-2018-3682

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2018-3682
value: HIGH

Trust: 1.0

NVD: CVE-2018-3682
value: HIGH

Trust: 0.8

CNVD: CNVD-2018-15554
value: HIGH

Trust: 0.6

CNNVD: CNNVD-201807-889
value: HIGH

Trust: 0.6

VULHUB: VHN-133713
value: MEDIUM

Trust: 0.1

nvd@nist.gov: CVE-2018-3682
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

CNVD: CNVD-2018-15554
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

VULHUB: VHN-133713
severity: MEDIUM
baseScore: 4.6
vectorString: AV:L/AC:L/AU:N/C:P/I:P/A:P
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 3.9
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2018-3682
baseSeverity: HIGH
baseScore: 8.2
vectorString: CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: HIGH
userInteraction: NONE
scope: CHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.5
impactScore: 6.0
version: 3.0

Trust: 1.8

sources: CNVD: CNVD-2018-15554 // VULHUB: VHN-133713 // JVNDB: JVNDB-2018-008010 // CNNVD: CNNVD-201807-889 // NVD: CVE-2018-3682

PROBLEMTYPE DATA

problemtype:CWE-269

Trust: 1.1

problemtype:CWE-264

Trust: 0.9

sources: VULHUB: VHN-133713 // JVNDB: JVNDB-2018-008010 // NVD: CVE-2018-3682

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201807-889

TYPE

permissions and access control issues

Trust: 0.6

sources: CNNVD: CNNVD-201807-889

CONFIGURATIONS

sources: JVNDB: JVNDB-2018-008010

PATCH

title:INTEL-SA-00130url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00130.html

Trust: 0.8

title:Patch for IntelServerBoard, ComputeModule, and ServerSystem denial of service vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/137777

Trust: 0.6

title:Intel Server Board , Compute Module and Server System Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=81952

Trust: 0.6

sources: CNVD: CNVD-2018-15554 // JVNDB: JVNDB-2018-008010 // CNNVD: CNNVD-201807-889

EXTERNAL IDS

db:NVDid:CVE-2018-3682

Trust: 3.1

db:JVNDBid:JVNDB-2018-008010

Trust: 0.8

db:CNNVDid:CNNVD-201807-889

Trust: 0.7

db:CNVDid:CNVD-2018-15554

Trust: 0.6

db:VULHUBid:VHN-133713

Trust: 0.1

sources: CNVD: CNVD-2018-15554 // VULHUB: VHN-133713 // JVNDB: JVNDB-2018-008010 // CNNVD: CNNVD-201807-889 // NVD: CVE-2018-3682

REFERENCES

url:https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00130.html

Trust: 2.3

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2018-3682

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2018-3682

Trust: 0.8

sources: CNVD: CNVD-2018-15554 // VULHUB: VHN-133713 // JVNDB: JVNDB-2018-008010 // CNNVD: CNNVD-201807-889 // NVD: CVE-2018-3682

SOURCES

db:CNVDid:CNVD-2018-15554
db:VULHUBid:VHN-133713
db:JVNDBid:JVNDB-2018-008010
db:CNNVDid:CNNVD-201807-889
db:NVDid:CVE-2018-3682

LAST UPDATE DATE

2024-11-23T22:22:01.949000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-15554date:2018-08-17T00:00:00
db:VULHUBid:VHN-133713date:2019-10-03T00:00:00
db:JVNDBid:JVNDB-2018-008010date:2018-10-05T00:00:00
db:CNNVDid:CNNVD-201807-889date:2019-10-23T00:00:00
db:NVDid:CVE-2018-3682date:2024-11-21T04:05:53.010

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-15554date:2018-08-17T00:00:00
db:VULHUBid:VHN-133713date:2018-07-10T00:00:00
db:JVNDBid:JVNDB-2018-008010date:2018-10-05T00:00:00
db:CNNVDid:CNNVD-201807-889date:2018-07-10T00:00:00
db:NVDid:CVE-2018-3682date:2018-07-10T21:29:01.107