SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2017-5691

Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security…

CRITICAL 9.0EPSS 1.44%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (1.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system state.

CVSS 3.0
9.0 CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
EPSS
1.44% probability · 72th percentile
CISA KEV
Not listed
Affected
intel/nuc7i3bnk bios · intel/nuc7i5bnk bios · intel/nuc7i7bnh bios · intel/stk2mv64cc bios · intel/stk2m3w64cc bios · intel/nuc6i7kyk bios · intel/nuc6i3syk bios · intel/nuc6i5syk bios · intel/r1304sposhor bios · intel/r1304sposhorr bios · intel/r1208sposhorr bios · intel/lr1304spcfg1r bios · intel/r1208sposhor bios · intel/s1200spsr bios · intel/s1200spor bios · intel/lr1304spcfg1 bios · intel/s1200spl bios · intel/s1200spo bios · intel/s1200sps bios · intel/r1304sposhbn bios · +2 more
Source
secure@intel.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.