CVE-2017-5722
Incorrect policy enforcement in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows attackers with local or physical access to bypass enforcement of integrity protections via manipulation of…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.35%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Incorrect policy enforcement in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows attackers with local or physical access to bypass enforcement of integrity protections via manipulation of firmware storage.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
- EPSS
- 0.35% probability · 28th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- intel/nuc7i7bnh firmware · intel/nuc7i5bnh firmware · intel/nuc7i5bnk firmware · intel/nuc7i3bnh firmware · intel/nuc7i3bnk firmware
- Source
- secure@intel.com
References
- http://www.securityfocus.com/bid/101236Third Party Advisory, VDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00084&languageid=en-frPatch, Third Party Advisory
- http://www.securityfocus.com/bid/101236Third Party Advisory, VDB Entry
- https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00084&languageid=en-frPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.