VYPR
Unrated severityNVD Advisory· Published Sep 12, 2018· Updated Sep 17, 2024

CVE-2018-3659

CVE-2018-3659

Description

A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Intel CSME and TXE firmware contain an information disclosure vulnerability in the PTT module that can be exploited by an unauthenticated attacker with physical access.

Vulnerability

An information disclosure vulnerability exists in the Intel Platform Trust Technology (PTT) module of the Intel Converged Security and Management Engine (CSME) firmware before version 12.0.5 and Intel Trusted Execution Engine (TXE) firmware before version 4.0. The vulnerability allows an unauthenticated user to potentially disclose sensitive information via physical access to the system. The flaw is present in the PTT implementation within the firmware [1].

Exploitation

The attacker requires physical access to the target system. No authentication is needed to exploit the vulnerability. The exact steps for exploitation are not detailed in the source, but the condition of physical access is the only prerequisite [1].

Impact

Successful exploitation leads to disclosure of information. The nature of the disclosed information (e.g., cryptographic keys, platform secrets) is not specified in the advisory. The attacker gains no additional privileges beyond reading potentially sensitive data accessible via the PTT module [1].

Mitigation

The vulnerability is fixed in Intel CSME firmware version 12.0.5 and Intel TXE firmware version 4.0. Users should update their firmware to these versions or later. Intel has released the advisory INTEL-SA-00142 detailing the update [1].

References
  1. INTEL-SA-00142

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3
  • Intel/TXEllm-create
    Range: <4.0
  • Intel/CSMEllm-fuzzy
    Range: <12.0.5
  • Intel Corporation/Intel(R) Platform Trust Technology (PTT)v5
    Range: Before version 12.0.5.

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.