CVE-2017-5700
published 2017-10-11CVE-2017-5700: Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows…
PriorityP339high8.4CVSS 3.0
AVLACLPRNUINSUCHIHAH
EPSS
0.38%
30.2th percentile
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.
Affected
51 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnh_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i3bnk_firmware | — | — |
| intel | nuc7i5bnh_firmware | — | — |
| intel | nuc7i5bnh_firmware | — | — |
| intel | nuc7i5bnh_firmware | — | — |
| intel | nuc7i5bnh_firmware | — | — |
| intel | nuc7i5bnh_firmware | — | — |
CVSS provenance
nvdv3.08.4HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vendor_cisco8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m2m4-m8jv-3qcw: Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and bel
ghsa_unreviewed·2022-05-13
CVE-2017-5700 [HIGH] CWE-522 GHSA-m2m4-m8jv-3qcw: Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and bel
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.
Cisco
Cisco StarOS CLI Command Injection Vulnerability
vendor_cisco·2017-07-05·CVSS 8.2
CVE-2017-6707 [HIGH] CWE-78 Cisco StarOS CLI Command Injection Vulnerability
Cisco StarOS CLI Command Injection Vulnerability
A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Core (VPC) Software could allow an authenticated, local attacker to break from the StarOS CLI of an affected system and execute arbitrary shell commands as a Linux root user on the system.
The vulnerability exists because the affected operating system does not sufficiently sanitize commands before inserting them into Linux shell commands. An attacker could exploit this vulnerability by submitting a crafted CLI command for execution in a Linux shell command as a root user. A successful exploit could allow the attacker to break from the StarOS CLI and execute arbitra
Cisco
Cisco StarOS SSH Privilege Escalation Vulnerability
vendor_cisco·2017-03-15·CVSS 8.8
CVE-2017-3819 [HIGH] CWE-264 Cisco StarOS SSH Privilege Escalation Vulnerability
Cisco StarOS SSH Privilege Escalation Vulnerability
A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, ASR 5700 Series devices, and Cisco Virtualized Packet Core could allow an authenticated, remote attacker to gain unrestricted, root shell access.
The vulnerability is due to missing input validation of parameters passed during SSH or SFTP login. An attacker could exploit this vulnerability by providing crafted user input to the SSH or SFTP command-line interface (CLI) during SSH or SFTP login. An exploit could allow an authenticated attacker to gain root privileges access on the router.
Note: Only traffic directed to the affected system can be used to exploit this vulnerability. This vulner
Cisco
Cisco StarOS CLI Command Injection Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-6707 Cisco StarOS CLI Command Injection Vulnerability
CVE-2017-6707: Cisco StarOS CLI Command Injection Vulnerability
A vulnerability in the CLI command-parsing code of the Cisco StarOS operating system for Cisco ASR 5000 Series, 5500 Series, and 5700 Series devices and Cisco Virtualized Packet Core (VPC) Software could allow an authenticated, local attacker to break from the StarOS CLI of an affected system and execute arbitrary shell commands as a Linux root user on the system. The vulnerability exists because the affected operating system does not sufficiently sanitize commands before inserting them into Linux shell commands. An attacker could exploit this vulnerability by submitting a crafted CLI command for execution in a Linux shell command as a root user. A successful exploit could allow the attacker to break from the StarOS CLI and ex
Cisco
Cisco StarOS SSH Privilege Escalation Vulnerability
vendor_cisco·CVSS 3.0
CVE-2017-3819 Cisco StarOS SSH Privilege Escalation Vulnerability
CVE-2017-3819: Cisco StarOS SSH Privilege Escalation Vulnerability
A privilege escalation vulnerability in the Secure Shell (SSH) subsystem in the StarOS operating system for Cisco ASR 5000 Series, ASR 5500 Series, ASR 5700 Series devices, and Cisco Virtualized Packet Core could allow an authenticated, remote attacker to gain unrestricted, root shell access. The vulnerability is due to missing input validation of parameters passed during SSH or SFTP login. An attacker could exploit this vulnerability by providing crafted user input to the SSH or SFTP command-line interface (CLI) during SSH or SFTP login. An exploit could allow an authenticated attacker to gain root privileges access on the router. Note: Only traffic directed to the affected system can be used to exploit this vulnerability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-11
Published