Vulnerabilities > Intel > Server Platform Services Firmware > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-14 CVE-2018-12208 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
low complexity
intel CWE-119
7.6
2019-03-14 CVE-2018-12191 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel products
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
low complexity
intel CWE-119
7.6
2018-09-12 CVE-2018-3655 Unspecified vulnerability in Intel products
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
low complexity
intel
7.3
2018-09-12 CVE-2018-3643 Unspecified vulnerability in Intel products
A vulnerability in Power Management Controller firmware in systems using specific Intel(R) Converged Security and Management Engine (CSME) before version 11.8.55, 11.11.55, 11.21.55, 12.0.6 or Intel(R) Server Platform Services firmware before version 4.x.04 may allow an attacker with administrative privileges to uncover certain platform secrets via local access or to potentially execute arbitrary code.
local
low complexity
intel
8.2
2017-11-21 CVE-2017-5709 Unspecified vulnerability in Intel Server Platform Services Firmware 4.0
Multiple privilege escalations in kernel in Intel Server Platform Services Firmware 4.0 allows unauthorized process to access privileged content via unspecified vector.
local
low complexity
intel
7.8
2017-11-21 CVE-2017-5706 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel Server Platform Services Firmware 4.0
Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code.
local
low complexity
intel CWE-119
7.8