← Vulnerability feed

Vulnerability record · CVE-2018-3652 · published 10 July 2018

CVE-2018-3652: Intel xeon e3 information exposure vulnerability

Intel · Xeon E3

Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.

7.6 CVSS 3.1 High EPSS 0.37% · top 71.2% CWE-200 · Information exposure
7.6CVSS 3.1 base score, v2 4.6
0.37%EPSS exploitation probability, 30 days
NoNot in CISA KEV
34Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.

CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected products

34 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-3652 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.3CVE-2018-3615Intel core i3 observable discrepancy vulnerabilitySystems with microprocessors utilizing speculative execution and Intel software guard extensions (Intel SGX) may allow unauthorized disclosure of inf…EPSS 6.3%5.6CVE-2018-3620Intel core i3 observable discrepancy vulnerabilitySystems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in th…EPSS 5.6%5.6CVE-2018-3646Intel core i3 information exposure vulnerabilitySystems with microprocessors utilizing speculative execution and address translations may allow unauthorized disclosure of information residing in th…EPSS 8.6%5.6CVE-2018-3693Intel atom c vulnerabilitySystems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker wi…EPSS 8.6%5.6CVE-2018-3640Intel atom c observable discrepancy vulnerabilitySystems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure…EPSS 7.6%5.6CVE-2018-9056Intel atom c information exposure vulnerabilitySystems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access v…EPSS 0.67%5.6CVE-2017-5715Intel CPUs speculative execution side-channel information disclosureCVE-2017-5715 is the Spectre variant 2 flaw in Intel microprocessors that use speculative execution and indirect branch prediction. A local attacker …EPSS 74%analysed5.6CVE-2017-5753Intel CPUs speculative execution side-channel information disclosure (Spectre v1)CVE-2017-5753 is a speculative execution and branch prediction side-channel flaw in Intel microprocessors that can leak information through observabl…EPSS 94%analysed

Source: NIST National Vulnerability Database (record CVE-2018-3652), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.