Vulnerability Database

383,371

Total vulnerabilities in the database

CVE-2018-3652 — intel / xeon_e3

Exposure of Sensitive Information to an Unauthorized Actor

Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.

  • Published: Jul 10, 2018
  • Updated: Sep 13, 2026
  • CVE: CVE-2018-3652
  • Severity: High
  • Exploit:
  • CISA KEV:

CVSS v3:

  • Severity: High
  • Score: 7.6
  • AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

CVSS v2:

  • Severity: Medium
  • Score: 4.6
  • AV:L/AC:L/Au:N/C:P/I:P/A:P

CWEs:

Software Affected versions
intel / xeon_e3 = 1505m_v6
intel / xeon_e3 = 1515m_v5
intel / xeon_e3 = 1535m_v5
intel / xeon_e3 = 1535m_v6
intel / xeon_e3 = 1545m_v5
intel / xeon_e3 = 1558l_v5
intel / xeon_e3 = 1565l_v5
intel / xeon_e3 = 1575m_v5
intel / xeon_e3 = 1578l_v5
intel / xeon_e3 = 1585_v5
intel / xeon_e3 = 1585l_v5
intel / xeon_gold = 5115
intel / xeon_gold = 5118
intel / xeon_gold = 5119t
intel / xeon_gold = 5120
intel / xeon_gold = 5120t
intel / xeon_gold = 5122
intel / xeon_gold = 6126
intel / xeon_gold = 6126f
intel / xeon_gold = 6126t
intel / xeon_gold = 6128
intel / xeon_gold = 6130
intel / xeon_gold = 6130f
intel / xeon_gold = 6130t
intel / xeon_gold = 6132
intel / xeon_gold = 6134
intel / xeon_gold = 6134m
intel / xeon_gold = 6136
intel / xeon_gold = 6138
intel / xeon_gold = 6138f
intel / xeon_gold = 6138p
intel / xeon_gold = 6138t
intel / xeon_gold = 6140
intel / xeon_gold = 6140m
intel / xeon_gold = 6142
intel / xeon_gold = 6142f
intel / xeon_gold = 6142m
intel / xeon_gold = 6144
intel / xeon_gold = 6146
intel / xeon_gold = 6148
intel / xeon_gold = 6148f
intel / xeon_gold = 6150
intel / xeon_gold = 6152
intel / xeon_gold = 6154
intel / xeon_platinum = 8153
intel / xeon_platinum = 8156
intel / xeon_platinum = 8158
intel / xeon_platinum = 8160
intel / xeon_platinum = 8160f
intel / xeon_platinum = 8160m
intel / xeon_platinum = 8160t
intel / xeon_platinum = 8164
intel / xeon_platinum = 8168
intel / xeon_platinum = 8170
intel / xeon_platinum = 8170m
intel / xeon_platinum = 8176
intel / xeon_platinum = 8176f
intel / xeon_platinum = 8176m
intel / xeon_platinum = 8180
intel / xeon_platinum = 8180m
intel / xeon_silver = 4108
intel / xeon_silver = 4109t
intel / xeon_silver = 4110
intel / xeon_silver = 4112
intel / xeon_silver = 4114
intel / xeon_silver = 4114t
intel / xeon_silver = 4116
intel / xeon_silver = 4116t
intel / xeon = d-1513n
intel / xeon = d-1518
intel / xeon = d-1520
intel / xeon = d-1521
intel / xeon = d-1523n
intel / xeon = d-1527
intel / xeon = d-1528
intel / xeon = d-1529
intel / xeon = d-1531
intel / xeon = d-1533n
intel / xeon = d-1537
intel / xeon = d-1539
intel / xeon = d-1540
intel / xeon = d-1541
intel / xeon = d-1543n
intel / xeon = d-1548
intel / xeon = d-1553n
intel / xeon = d-1557
intel / xeon = d-1559
intel / xeon = d-1567
intel / xeon = d-1571
intel / xeon = d-1577
intel / xeon = d-2123it
intel / xeon = d-2141i
intel / xeon = d-2142it
intel / xeon = d-2143it
intel / xeon = d-2145nt
intel / xeon = d-2146nt
intel / xeon = d-2161i
intel / xeon = d-2163it
intel / xeon = d-2166nt
intel / xeon = d-2173it
intel / xeon = d-2177nt
intel / xeon = d-2183it
intel / xeon = d-2187nt
intel / atom_c = c2308
intel / atom_c = c2316
intel / atom_c = c2338
intel / atom_c = c2350
intel / atom_c = c2358
intel / atom_c = c2508
intel / atom_c = c2516
intel / atom_c = c2518
intel / atom_c = c2530
intel / atom_c = c2538
intel / atom_c = c2550
intel / atom_c = c2558
intel / atom_c = c2718
intel / atom_c = c2730
intel / atom_c = c2738
intel / atom_c = c2750
intel / atom_c = c2758
intel / atom_c = c3308
intel / atom_c = c3336
intel / atom_c = c3338
intel / atom_c = c3508
intel / atom_c = c3538
intel / atom_c = c3558
intel / atom_c = c3708
intel / atom_c = c3750
intel / atom_c = c3758
intel / atom_c = c3808
intel / atom_c = c3830
intel / atom_c = c3850
intel / atom_c = c3858
intel / atom_c = c3950
intel / atom_c = c3955
intel / atom_c = c3958

Frequently Asked Questions

A security vulnerability is a weakness in software, hardware, or configuration that can be exploited to compromise confidentiality, integrity, or availability. Many vulnerabilities are tracked as CVEs (Common Vulnerabilities and Exposures), which provide a standardized identifier so teams can coordinate patching, mitigation, and risk assessment across tools and vendors.

CVSS (Common Vulnerability Scoring System) estimates technical severity, but it doesn't automatically equal business risk. Prioritize using context like internet exposure, affected asset criticality, known exploitation (proof-of-concept or in-the-wild), and whether compensating controls exist. A "Medium" CVSS on an exposed, production system can be more urgent than a "Critical" on an isolated, non-production host.

A vulnerability is the underlying weakness. An exploit is the method or code used to take advantage of it. A zero-day is a vulnerability that is unknown to the vendor or has no publicly available fix when attackers begin using it. In practice, risk increases sharply when exploitation becomes reliable or widespread.

Recurring findings usually come from incomplete Asset Discovery, inconsistent patch management, inherited images, and configuration drift. In modern environments, you also need to watch the software supply chain: dependencies, containers, build pipelines, and third-party services can reintroduce the same weakness even after you patch a single host. Unknown or unmanaged assets (often called Shadow IT) are a common reason the same issues resurface.

Use a simple, repeatable triage model: focus first on externally exposed assets, high-value systems (identity, VPN, email, production), vulnerabilities with known exploits, and issues that enable remote code execution or privilege escalation. Then enforce patch SLAs and track progress using consistent metrics so remediation is steady, not reactive.

SynScan combines attack surface monitoring and continuous security auditing to keep your inventory current, flag high-impact vulnerabilities early, and help you turn raw findings into a practical remediation plan.