Severity
8.4HIGH
EPSS
0.1%
top 84.14%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateMay 13

Description

Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.5 | Impact: 5.9

Affected Packages6 packages

NVDintel/nuc7i3bnh_firmware10 versions+9
NVDintel/nuc7i3bnk_firmware10 versions+9
NVDintel/nuc7i5bnh_firmware10 versions+9
NVDintel/nuc7i5bnk_firmware10 versions+9
NVDintel/nuc7i7bnh_firmware10 versions+9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m2m4-m8jv-3qcw: Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and bel2022-05-13
CVEList
CVE-2017-5700: Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and bel2017-10-11

📋Vendor Advisories

2
Cisco
Cisco StarOS CLI Command Injection Vulnerability2017-07-05
Cisco
Cisco StarOS SSH Privilege Escalation Vulnerability2017-03-15
CVE-2017-5700 (HIGH CVSS 8.4) | Insufficient protection of password | cvebase.io