CVE-2018-12173: Intel Compute Module HNS2600BP Firmware

High severity, CVSS 7.6. EPSS: 0.4% chance of exploitation in the next 30 days.

Insufficient access protection in firmware in Intel Server Board, Intel Server System and Intel Compute Module before firmware version 00.01.0014 may allow an unauthenticated attacker to potentially execute arbitrary code resulting in information disclosure, escalation of privilege and/or denial of service via local access.

Affected products

  • Intel Compute Module HNS2600BP Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Compute Module HNS2600BPR Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server Board s2600bp Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server Board s2600bpr Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server Board s2600st Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server Board s2600str Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server Board s2600wf Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server Board s2600wfr Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server System h2000g Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server System h2000gr Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server System r1000wf Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server System r1000wfr Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server System r2000wf Firmware: before 00.01.0014 (fixed in 00.01.0014)
  • Intel Server System r2000wfr Firmware: before 00.01.0014 (fixed in 00.01.0014)

Published 2018-10-10. Last modified 2026-06-17.