CVE-2018-3652

Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.

Published: 2018-07-10 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2018-3652 is rated Moderate Risk (40.4/100): CVSS High severity, with low exploitation likelihood (EPSS 0.36%). Mandatory action: Review affected assets and schedule remediation.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2018-3652

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.14% 0.36% +0.22%
2 2025-03-30 0.24% 0.14% -0.09%
3 2025-03-29 0.24%

Full EPSS history (6 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2018-3652

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
7.6 3.1 HIGH
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Click to expand
Attack vector (AV:P)
Hands-on access—USB, keyboard, opening the case—not something you do purely over the wire.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:N)
No account or special rights needed—anonymous or random user is enough.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:H)
Serious risk that confidential data gets exposed in a big way.
Integrity (I:H)
They could widely tamper with or forge data—trust in the data is badly hurt.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
0.9 6.0 [email protected]
4.6 2.0 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
3.9 6.4 [email protected]

Weakness enumeration for CVE-2018-3652

Affected software / configurations for CVE-2018-3652

Vendor Product Version Raw CPE
intel xeon_e3 1505m_v6 cpe:2.3:h:intel:xeon_e3:1505m_v6:*:*:*:*:*:*:*
intel xeon_e3 1515m_v5 cpe:2.3:h:intel:xeon_e3:1515m_v5:*:*:*:*:*:*:*
intel xeon_e3 1535m_v5 cpe:2.3:h:intel:xeon_e3:1535m_v5:*:*:*:*:*:*:*
intel xeon_e3 1535m_v6 cpe:2.3:h:intel:xeon_e3:1535m_v6:*:*:*:*:*:*:*
intel xeon_e3 1545m_v5 cpe:2.3:h:intel:xeon_e3:1545m_v5:*:*:*:*:*:*:*
intel xeon_e3 1558l_v5 cpe:2.3:h:intel:xeon_e3:1558l_v5:*:*:*:*:*:*:*
intel xeon_e3 1565l_v5 cpe:2.3:h:intel:xeon_e3:1565l_v5:*:*:*:*:*:*:*
intel xeon_e3 1575m_v5 cpe:2.3:h:intel:xeon_e3:1575m_v5:*:*:*:*:*:*:*
intel xeon_e3 1578l_v5 cpe:2.3:h:intel:xeon_e3:1578l_v5:*:*:*:*:*:*:*
intel xeon_e3 1585_v5 cpe:2.3:h:intel:xeon_e3:1585_v5:*:*:*:*:*:*:*
intel xeon_e3 1585l_v5 cpe:2.3:h:intel:xeon_e3:1585l_v5:*:*:*:*:*:*:*
intel xeon_e3_1220_v5 cpe:2.3:h:intel:xeon_e3_1220_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1220_v6 cpe:2.3:h:intel:xeon_e3_1220_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1225_v5 cpe:2.3:h:intel:xeon_e3_1225_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1225_v6 cpe:2.3:h:intel:xeon_e3_1225_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1230_v5 cpe:2.3:h:intel:xeon_e3_1230_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1230_v6 cpe:2.3:h:intel:xeon_e3_1230_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1235l_v5 cpe:2.3:h:intel:xeon_e3_1235l_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1240_v5 cpe:2.3:h:intel:xeon_e3_1240_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1240_v6 cpe:2.3:h:intel:xeon_e3_1240_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1240l_v5 cpe:2.3:h:intel:xeon_e3_1240l_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1245_v5 cpe:2.3:h:intel:xeon_e3_1245_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1245_v6 cpe:2.3:h:intel:xeon_e3_1245_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1260l_v5 cpe:2.3:h:intel:xeon_e3_1260l_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1268l_v5 cpe:2.3:h:intel:xeon_e3_1268l_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1270_v5 cpe:2.3:h:intel:xeon_e3_1270_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1270_v6 cpe:2.3:h:intel:xeon_e3_1270_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1275_v5 cpe:2.3:h:intel:xeon_e3_1275_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1275_v6 cpe:2.3:h:intel:xeon_e3_1275_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1280_v5 cpe:2.3:h:intel:xeon_e3_1280_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1280_v6 cpe:2.3:h:intel:xeon_e3_1280_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1285_v6 cpe:2.3:h:intel:xeon_e3_1285_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1501l_v6 cpe:2.3:h:intel:xeon_e3_1501l_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1501m_v6 cpe:2.3:h:intel:xeon_e3_1501m_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1505l_v5 cpe:2.3:h:intel:xeon_e3_1505l_v5:-:*:*:*:*:*:*:*
intel xeon_e3_1505l_v6 cpe:2.3:h:intel:xeon_e3_1505l_v6:-:*:*:*:*:*:*:*
intel xeon_e3_1505m_v5 cpe:2.3:h:intel:xeon_e3_1505m_v5:-:*:*:*:*:*:*:*
intel xeon_bronze_3104 cpe:2.3:h:intel:xeon_bronze_3104:-:*:*:*:*:*:*:*
intel xeon_bronze_3106 cpe:2.3:h:intel:xeon_bronze_3106:-:*:*:*:*:*:*:*
intel xeon_gold 5115 cpe:2.3:h:intel:xeon_gold:5115:*:*:*:*:*:*:*
intel xeon_gold 5118 cpe:2.3:h:intel:xeon_gold:5118:*:*:*:*:*:*:*
intel xeon_gold 5119t cpe:2.3:h:intel:xeon_gold:5119t:*:*:*:*:*:*:*
intel xeon_gold 5120 cpe:2.3:h:intel:xeon_gold:5120:*:*:*:*:*:*:*
intel xeon_gold 5120t cpe:2.3:h:intel:xeon_gold:5120t:*:*:*:*:*:*:*
intel xeon_gold 5122 cpe:2.3:h:intel:xeon_gold:5122:*:*:*:*:*:*:*
intel xeon_gold 6126 cpe:2.3:h:intel:xeon_gold:6126:*:*:*:*:*:*:*
intel xeon_gold 6126f cpe:2.3:h:intel:xeon_gold:6126f:*:*:*:*:*:*:*
intel xeon_gold 6126t cpe:2.3:h:intel:xeon_gold:6126t:*:*:*:*:*:*:*
intel xeon_gold 6128 cpe:2.3:h:intel:xeon_gold:6128:*:*:*:*:*:*:*
intel xeon_gold 6130 cpe:2.3:h:intel:xeon_gold:6130:*:*:*:*:*:*:*
intel xeon_gold 6130f cpe:2.3:h:intel:xeon_gold:6130f:*:*:*:*:*:*:*
intel xeon_gold 6130t cpe:2.3:h:intel:xeon_gold:6130t:*:*:*:*:*:*:*
intel xeon_gold 6132 cpe:2.3:h:intel:xeon_gold:6132:*:*:*:*:*:*:*
intel xeon_gold 6134 cpe:2.3:h:intel:xeon_gold:6134:*:*:*:*:*:*:*
intel xeon_gold 6134m cpe:2.3:h:intel:xeon_gold:6134m:*:*:*:*:*:*:*
intel xeon_gold 6136 cpe:2.3:h:intel:xeon_gold:6136:*:*:*:*:*:*:*
intel xeon_gold 6138 cpe:2.3:h:intel:xeon_gold:6138:*:*:*:*:*:*:*
intel xeon_gold 6138f cpe:2.3:h:intel:xeon_gold:6138f:*:*:*:*:*:*:*
intel xeon_gold 6138p cpe:2.3:h:intel:xeon_gold:6138p:*:*:*:*:*:*:*
intel xeon_gold 6138t cpe:2.3:h:intel:xeon_gold:6138t:*:*:*:*:*:*:*
intel xeon_gold 6140 cpe:2.3:h:intel:xeon_gold:6140:*:*:*:*:*:*:*
intel xeon_gold 6140m cpe:2.3:h:intel:xeon_gold:6140m:*:*:*:*:*:*:*
intel xeon_gold 6142 cpe:2.3:h:intel:xeon_gold:6142:*:*:*:*:*:*:*
intel xeon_gold 6142f cpe:2.3:h:intel:xeon_gold:6142f:*:*:*:*:*:*:*
intel xeon_gold 6142m cpe:2.3:h:intel:xeon_gold:6142m:*:*:*:*:*:*:*
intel xeon_gold 6144 cpe:2.3:h:intel:xeon_gold:6144:*:*:*:*:*:*:*
intel xeon_gold 6146 cpe:2.3:h:intel:xeon_gold:6146:*:*:*:*:*:*:*
intel xeon_gold 6148 cpe:2.3:h:intel:xeon_gold:6148:*:*:*:*:*:*:*
intel xeon_gold 6148f cpe:2.3:h:intel:xeon_gold:6148f:*:*:*:*:*:*:*
intel xeon_gold 6150 cpe:2.3:h:intel:xeon_gold:6150:*:*:*:*:*:*:*
intel xeon_gold 6152 cpe:2.3:h:intel:xeon_gold:6152:*:*:*:*:*:*:*
intel xeon_gold 6154 cpe:2.3:h:intel:xeon_gold:6154:*:*:*:*:*:*:*
intel xeon_platinum 8153 cpe:2.3:h:intel:xeon_platinum:8153:*:*:*:*:*:*:*
intel xeon_platinum 8156 cpe:2.3:h:intel:xeon_platinum:8156:*:*:*:*:*:*:*
intel xeon_platinum 8158 cpe:2.3:h:intel:xeon_platinum:8158:*:*:*:*:*:*:*
intel xeon_platinum 8160 cpe:2.3:h:intel:xeon_platinum:8160:*:*:*:*:*:*:*
intel xeon_platinum 8160f cpe:2.3:h:intel:xeon_platinum:8160f:*:*:*:*:*:*:*
intel xeon_platinum 8160m cpe:2.3:h:intel:xeon_platinum:8160m:*:*:*:*:*:*:*
intel xeon_platinum 8160t cpe:2.3:h:intel:xeon_platinum:8160t:*:*:*:*:*:*:*
intel xeon_platinum 8164 cpe:2.3:h:intel:xeon_platinum:8164:*:*:*:*:*:*:*

References for CVE-2018-3652

cvelogic Threat Intelligence