Vulnerability CVE-2017-5691


Published: 2017-07-26

Description:
Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system state.

Type:

CWE-noinfo

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Intel -> S1200sps bios 
Intel -> Nuc6i5syk bios 
Intel -> R1208sposhor bios 
Intel -> Nuc7i7bnh bios 
Intel -> R1208sposhorr bios 
Intel -> R1304sposhbn bios 
Intel -> S1200spo bios 
Intel -> Lr1304spcfg1r bios 
Intel -> R1304sposhbnr bios 
Intel -> R1304sposhor bios 
Intel -> S1200spor bios 
Intel -> R1304sposhorr bios 
Intel -> Stk2m3w64cc bios 
Intel -> S1200spl bios 
Intel -> S1200splr bios 
Intel -> Stk2mv64cc bios 
Intel -> Nuc6i3syk bios 
Intel -> S1200spsr bios 
Intel -> Lr1304spcfg1 bios 
Intel -> Nuc7i3bnk bios 
Intel -> Nuc7i5bnk bios 
Intel -> Nuc6i7kyk bios 

 References:
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesb3p03767en_us
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00076&languageid=en-fr
https://support.lenovo.com/us/en/product_security/LEN-15184

Copyright 2024, cxsecurity.com

 

Back to Top