Medium severity6.7NVD Advisory· Published Sep 12, 2018· Updated Jun 17, 2026
CVE-2018-3657
CVE-2018-3657
Description
Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execution privilege via local access.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
17- cpe:2.3:a:intel:converged_security_management_engine_firmware:*:*:*:*:*:*:*:*Range: >=11.0.0,<12.0.5
- cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:*Range: <12.0.5
- cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*Range: >=9.0.0.0,<11.0
- cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:*Range: <22.01.06
- cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:*Range: <21.01.09
- cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:*Range: <21.01.09
- cpe:2.3:o:siemens:simatic_ipc547e_firmware:*:*:*:*:*:*:*:*Range: <r1.30.0
- cpe:2.3:o:siemens:simatic_ipc627d_firmware:*:*:*:*:*:*:*:*Range: <19.02.11
- cpe:2.3:o:siemens:simatic_ipc647d_firmware:*:*:*:*:*:*:*:*Range: <19.01.14
- cpe:2.3:o:siemens:simatic_ipc677d_firmware:*:*:*:*:*:*:*:*Range: <19.02.11
- cpe:2.3:o:siemens:simatic_ipc827d_firmware:*:*:*:*:*:*:*:*Range: <19.02.11
- cpe:2.3:o:siemens:simatic_ipc847d_firmware:*:*:*:*:*:*:*:*Range: <19.01.14
- cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:*Range: <23.01.04
- cpe:2.3:o:siemens:simatic_pc547g_firmware:*:*:*:*:*:*:*:*Range: <r1.23.0
- Intel Corporation/Intel(R) Active Management Technologyv5Range: Versions before version 12.0.5.
Patches
Vulnerability mechanics
References
6- cert-portal.siemens.com/productcert/pdf/ssa-377318.pdfnvdPatchThird Party Advisory
- www.securityfocus.com/bid/106996nvdThird Party AdvisoryVDB Entry
- ics-cert.us-cert.gov/advisories/ICSA-19-043-05nvdThird Party AdvisoryUS Government Resource
- security.netapp.com/advisory/ntap-20180924-0003/nvdThird Party Advisory
- support.hpe.com/hpsc/doc/public/displaynvdThird Party Advisory
- www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00141.htmlnvdVendor Advisory
News mentions
0No linked articles in our index yet.