Intel Nuc7I5Bnh Firmware vulnerabilities

5 known vulnerabilities affecting intel/nuc7i5bnh_firmware.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH4MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2020-8742MEDIUMCVSS 6.7fixed in bnkbl357.86a2020-08-13
CVE-2020-8742 [MEDIUM] CWE-20 CVE-2020-8742: Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potential Improper input validation in the firmware for Intel(R) NUCs may allow a privileged user to potentially enable escalation of privilege via local access.
nvd
CVE-2017-5722HIGHCVSS 7.5vayaplcel.86a.0041vbnkbl357.86a.0052+8 more2017-10-11
CVE-2017-5722 [HIGH] CWE-269 CVE-2017-5722: Incorrect policy enforcement in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH Incorrect policy enforcement in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows attackers with local or physical access to bypass enforcement of integrity protections via manipulation of firmware storage.
nvd
CVE-2017-5701HIGHCVSS 7.1vayaplcel.86a.0041vbnkbl357.86a.0052+8 more2017-10-11
CVE-2017-5701 [HIGH] CVE-2017-5701: Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5 Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows an attacker with physical presence to run arbitrary code via unauthorized firmware modification during BIOS Recovery.
nvd
CVE-2017-5700HIGHCVSS 8.4vayaplcel.86a.0041vbnkbl357.86a.0052+8 more2017-10-11
CVE-2017-5700 [HIGH] CWE-522 CVE-2017-5700: Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.
nvd
CVE-2017-5721HIGHCVSS 7.5vayaplcel.86a.0041vbnkbl357.86a.0052+8 more2017-10-11
CVE-2017-5721 [HIGH] CWE-20 CVE-2017-5721: Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BN Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to execute arbitrary code via manipulation of memory.
nvd