IBM Support

Security Bulletin: IBM has released Unified Extensible Firmware Interface (UEFI) fixes in response to TianoCore EDK II BIOS Vulnerability (CVE-2018-12182)

Security Bulletin


Summary

IBM has released the following Unified Extensible Firmware Interface (UEFI) fixes for System x and Flex systems in response to the TianoCore EDK II BIOS Vulnerability listed below.

Vulnerability Details

CVEID: CVE-2018-12182
DESCRIPTION: TianoCore EDK II BIOS could allow a local authenticated attacker to gain elevated privileges on the system, caused by improper memory write check in SMM service. By sending a specially-crafted request, an attacker could exploit this vulnerability to gain elevated privileges, obtain sensitive information or cause a denial of service condition.
CVSS Base Score: 8.2
CVSS Temporal Score: See https://exchange.xforce.ibmcloud.com/vulnerabilities/161214 for the current score
CVSS Environmental Score*: Undefined
CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H)

Affected Products and Versions

Product

Affected Version

Flex System x280, x480, x880 7903

n2e1

System x3850 x6 3837/3839
System x3950 x6 3839

a8e1

Remediation/Fixes

Firmware fix versions are available on Fix Central:  http://www.ibm.com/support/fixcentral/

Product

Fixed Version

Flex System x280, x480, x880 7903
(ibm_fw_uefi_n2e134d-2.10_anyos_32-64)
n2e134d-2.10
System x3850 x6 3837/3839
System x3950 x6 3839
(ibm_fw_uefi_a8e132d-1.90_anyos_32-64)
a8e132d-1.90

Workarounds and Mitigations

None

Get Notified about Future Security Bulletins

References

Off

Change History

15 July 2019: Original version published

*The CVSS Environment Score is customer environment specific and will ultimately impact the Overall CVSS Score. Customers can evaluate the impact of this vulnerability in their environments by accessing the links in the Reference section of this Security Bulletin.

Disclaimer

Review the IBM security bulletin disclaimer and definitions regarding your responsibilities for assessing potential impact of security vulnerabilities to your environment.

Internal Use Only

[{"Business Unit":{"code":"BU016","label":"Multiple Vendor Support"},"Product":{"code":"HW19X","label":"System x-\u003EMicrosoft Datacenter"},"Component":"UEFI in System x3850 x6 3837\/3839 and System x3950 x6 3839","Platform":[{"code":"PF009","label":"Firmware"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"","label":""}},{"Business Unit":{"code":"BU050","label":"BU NOT IDENTIFIED"},"Product":{"code":"SSWLYD","label":"PureFlex System \u0026 Flex System"},"Component":"UEFI in Flex System x280, x480, x880 7903","Platform":[{"code":"PF009","label":"Firmware"}],"Version":"All Versions","Edition":"","Line of Business":{"code":"","label":""}}]

Document Information

Modified date:
15 July 2019

UID

ibm10958911