CVE-2017-5706
published 2017-11-21CVE-2017-5706: Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code.
PriorityP338high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
EPSS
0.69%
48.3th percentile
Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| intel | server_platform_services_firmware | — | — |
| intel_corporation | server_platform_services | — | — |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC, SIMOTION, and SINUMERIK (Update A)
cisa_ics·2018-03-01
Siemens SIMATIC, SIMOTION, and SINUMERIK (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SIMATIC, SIMOTION, and SINUMERIK (Update A)
Last RevisedApril 19, 2018
Alert CodeICSA-18-060-01
## 1. EXECUTIVE SUMMARY
## CVSS v3 8.2
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-18-060-01 Siemens SIMATIC, SIMOTION, and SINUMERIK that was published March 01, 2018, on the NCCIC/ICS-CERT website.
## 3. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in execution of arbitrary code, extended privileges, and unauthenticated access to sensitive data.
## 4. TECHNICAL DETAILS
## 4.1 AFFECT
GHSA
GHSA-55pw-cf45-3838: Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4
ghsa_unreviewed·2022-05-14
CVE-2017-5706 [HIGH] CWE-119 GHSA-55pw-cf45-3838: Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4
Multiple buffer overflows in kernel in Intel Server Platform Services Firmware 4.0 allow attacker with local access to the system to execute arbitrary code.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/101906http://www.securitytracker.com/id/1039955https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfhttps://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frhttps://security.netapp.com/advisory/ntap-20171120-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03798en_ushttps://twitter.com/PTsecurity_UK/status/938447926128291842https://www.asus.com/News/wzeltG5CjYaIwGJ0http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.htmlhttp://www.securityfocus.com/bid/101906http://www.securitytracker.com/id/1039955https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdfhttps://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&languageid=en-frhttps://security.netapp.com/advisory/ntap-20171120-0001/https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03798en_ushttps://twitter.com/PTsecurity_UK/status/938447926128291842https://www.asus.com/News/wzeltG5CjYaIwGJ0
2017-11-21
Published