CVE-2018-3616

Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain the TLS session key via the network.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc547e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pc547e:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_pc547g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc547g:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc627d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc627d:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc647d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647d:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc677d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc677d:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc827d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc827d:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc847d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847d:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:*

History

17 Aug 2023, 17:43

Type Values Removed Values Added
First Time Intel active Management Technology Firmware
Intel manageability Engine Firmware
CPE cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*

26 May 2021, 16:11

Type Values Removed Values Added
CPE cpe:2.3:h:siemens:simatic_fieldpg_m5:-:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_fieldpg_m5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*

Information

Published : 2018-09-12 19:29

Updated : 2023-12-10 12:44


NVD link : CVE-2018-3616

Mitre link : CVE-2018-3616

CVE.ORG link : CVE-2018-3616


JSON object : View

Products Affected

intel

  • converged_security_management_engine_firmware
  • active_management_technology_firmware
  • manageability_engine_firmware

siemens

  • simatic_ipc427e
  • simatic_ipc547e_firmware
  • simatic_ipc627d
  • simatic_itp1000
  • simatic_field_pg_m5_firmware
  • simatic_ipc647d
  • simatic_itp1000_firmware
  • simatic_ipc677d
  • simatic_ipc427e_firmware
  • simatic_ipc827d
  • simatic_ipc477e
  • simatic_field_pg_m5
  • simatic_ipc627d_firmware
  • simatic_ipc647d_firmware
  • simatic_ipc677d_firmware
  • simatic_pc547e
  • simatic_ipc847d_firmware
  • simatic_ipc847d
  • simatic_ipc827d_firmware
  • simatic_ipc477e_firmware
  • simatic_ipc547g
  • simatic_pc547g_firmware