Lucene search

K
cveIntelCVE-2017-5705
HistoryNov 21, 2017 - 2:29 p.m.

CVE-2017-5705

2017-11-2114:29:00
CWE-119
intel
web.nvd.nist.gov
82
cve-2017-5705
buffer overflow
intel
me firmware
local access
arbitrary code
nvd

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

5.2%

Multiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code.

Affected configurations

Nvd
Vulners
Node
intelmanageability_engine_firmwareMatch11.0
OR
intelmanageability_engine_firmwareMatch11.5
OR
intelmanageability_engine_firmwareMatch11.6
OR
intelmanageability_engine_firmwareMatch11.7
OR
intelmanageability_engine_firmwareMatch11.10
OR
intelmanageability_engine_firmwareMatch11.20
VendorProductVersionCPE
intelmanageability_engine_firmware11.0cpe:2.3:o:intel:manageability_engine_firmware:11.0:*:*:*:*:*:*:*
intelmanageability_engine_firmware11.5cpe:2.3:o:intel:manageability_engine_firmware:11.5:*:*:*:*:*:*:*
intelmanageability_engine_firmware11.6cpe:2.3:o:intel:manageability_engine_firmware:11.6:*:*:*:*:*:*:*
intelmanageability_engine_firmware11.7cpe:2.3:o:intel:manageability_engine_firmware:11.7:*:*:*:*:*:*:*
intelmanageability_engine_firmware11.10cpe:2.3:o:intel:manageability_engine_firmware:11.10:*:*:*:*:*:*:*
intelmanageability_engine_firmware11.20cpe:2.3:o:intel:manageability_engine_firmware:11.20:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Manageability Engine",
    "vendor": "Intel Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "11.0/11.5/11.6/11.7/11.10/11.20"
      }
    ]
  }
]

CVSS2

7.2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

High

EPSS

0

Percentile

5.2%