CVE-2017-5701

3 documents3 sources
Severity
7.1HIGH
EPSS
0.1%
top 77.60%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 11
Latest updateMay 13

Description

Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows an attacker with physical presence to run arbitrary code via unauthorized firmware modification during BIOS Recovery.

CVSS vector

CVSS:3.0/AV:P/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HExploitability: 0.5 | Impact: 6.0

Affected Packages6 packages

NVDintel/nuc7i3bnh_firmware10 versions+9
NVDintel/nuc7i3bnk_firmware10 versions+9
NVDintel/nuc7i5bnh_firmware10 versions+9
NVDintel/nuc7i5bnk_firmware10 versions+9
NVDintel/nuc7i7bnh_firmware10 versions+9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-rqxq-8q8c-r6x4: Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows an2022-05-13
CVEList
CVE-2017-5701: Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows an2017-10-11
CVE-2017-5701 (HIGH CVSS 7.1) | Insecure platform configuration in | cvebase.io