Vulnerability CVE-2017-5691


Published: 2017-07-26

Description:
Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system state.

Vendor: Intel
Product: R1304sposhorr bios 
Product: Nuc6i5syk bios 
Product: R1208sposhorr bios 
Product: Nuc7i3bnk bios 
Product: S1200splr bios 
Product: R1304sposhbn bios 
Product: R1304sposhbnr bios 
Product: Nuc6i7kyk bios 
Product: Nuc6i3syk bios 
Product: R1304sposhor bios 
Product: Stk2m3w64cc bios 
Product: R1208sposhor bios 
Product: Lr1304spcfg1 bios 
Product: S1200spl bios 
Product: Nuc7i7bnh bios 
Product: S1200spo bios 
Product: Nuc7i5bnk bios 
Product: Stk2mv64cc bios 
Product: Lr1304spcfg1r bios 
Product: S1200spor bios 
Product: S1200sps bios 
Product: S1200spsr bios 

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete

 References:
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesb3p03767en_us
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00076&languageid=en-fr
https://support.lenovo.com/us/en/product_security/LEN-15184

Related CVE
CVE-2019-11184
A race condition in specific microprocessors using Intel (R) DDIO cache allocation and RDMA may allow an authenticated user to potentially enable partial information disclosure via adjacent access.
CVE-2019-11166
Improper file permissions in the installer for Intel(R) Easy Streaming Wizard before version 2.1.0731 may allow an authenticated user to potentially enable escalation of privilege via local attack.
CVE-2019-11163
Insufficient access control in a hardware abstraction driver for Intel(R) Processor Identification Utility for Windows before version 6.1.0731 may allow an authenticated user to potentially enable escalation of privilege, denial of service or informa...
CVE-2019-11148
Improper permissions in the installer for Intel(R) Remote Displays SDK before version 2.0.1 R2 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2019-11143
Improper permissions in the software installer for Intel(R) Authenticate before 3.8 may allow an authenticated user to potentially enable escalation of privilege via local access.
CVE-2019-11140
Insufficient session validation in system firmware for Intel(R) NUC may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.
CVE-2019-0173
Authentication bypass in the web console for Intel(R) Raid Web Console 2 all versions may allow an unauthenticated attacker to potentially enable disclosure of information via network access.
CVE-2019-11129
Out of bound read/write in system firmware for Intel(R) NUC Kit may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local access.

Copyright 2019, cxsecurity.com

 

Back to Top