Vulnerability CVE-2017-5721


Published: 2017-10-10   Modified: 2017-10-11

Description:
Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to execute arbitrary code via manipulation of memory.

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:L/AC:M/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.4/10
6.4/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial
Affected software
Intel -> Nuc7i3bnh firmware 
Intel -> Nuc7i3bnk firmware 
Intel -> Nuc7i5bnh firmware 
Intel -> Nuc7i5bnk firmware 
Intel -> Nuc7i7bnh firmware 

 References:
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00084&languageid=en-fr

Copyright 2024, cxsecurity.com

 

Back to Top