Vulnerability Name:

CVE-2017-5691 (CCN-129610)

Assigned:2017-07-26
Published:2017-07-26
Updated:2019-10-03
Summary:Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system state.
CVSS v3 Severity:9.0 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H)
7.8 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.7 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
6.8 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Gain Privileges
References:Source: MITRE
Type: CNA
CVE-2017-5691

Source: XF
Type: UNKNOWN
lenovo-cve20175691-priv-esc(129610)

Source: CONFIRM
Type: Third Party Advisory
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesb3p03767en_us

Source: CONFIRM
Type: Vendor Advisory
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00076&languageid=en-fr

Source: CCN
Type: Lenovo Security Advisory: LEN-15184
Intel SGX Update and Attestation Key Recovery

Source: CONFIRM
Type: UNKNOWN
https://support.lenovo.com/us/en/product_security/LEN-15184

Vulnerable Configuration:Configuration 1:
  • cpe:/o:intel:nuc7i3bnk_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:nuc7i3bnk:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:intel:nuc7i5bnk_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:nuc7i5bnk:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:intel:nuc7i7bnh_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:nuc7i7bnh:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:intel:stk2mv64cc_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:stk2mv64cc:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:intel:stk2m3w64cc_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:stk2m3w64cc:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:intel:nuc6i7kyk_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:nuc6i7kyk:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:intel:nuc6i3syk_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:nuc6i3syk:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:intel:nuc6i5syk_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:nuc6i5syk:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:intel:r1304sposhor_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:r1304sposhor:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:intel:r1304sposhorr_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:r1304sposhorr:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:intel:r1208sposhorr_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:r1208sposhorr:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:intel:lr1304spcfg1r_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:lr1304spcfg1r:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:intel:r1208sposhor_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:r1208sposhor:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:intel:s1200spsr_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:s1200spsr:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:intel:s1200spor_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:s1200spor:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:intel:lr1304spcfg1_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:lr1304spcfg1:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:intel:s1200spl_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:s1200spl:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:intel:s1200spo_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:s1200spo:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:intel:s1200sps_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:s1200sps:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:intel:r1304sposhbn_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:r1304sposhbn:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:intel:s1200splr_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:s1200splr:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:intel:r1304sposhbnr_bios:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:intel:r1304sposhbnr:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/h:lenovo:thinkcentre_m6600:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:thinkpad_t460:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:thinkpad_t460p:-:*:*:*:*:*:*:*
  • OR cpe:/h:lenovo:thinkpad_t460s:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    intel nuc7i3bnk bios -
    intel nuc7i3bnk -
    intel nuc7i5bnk bios -
    intel nuc7i5bnk -
    intel nuc7i7bnh bios -
    intel nuc7i7bnh -
    intel stk2mv64cc bios -
    intel stk2mv64cc -
    intel stk2m3w64cc bios -
    intel stk2m3w64cc -
    intel nuc6i7kyk bios -
    intel nuc6i7kyk -
    intel nuc6i3syk bios -
    intel nuc6i3syk -
    intel nuc6i5syk bios -
    intel nuc6i5syk -
    intel r1304sposhor bios -
    intel r1304sposhor -
    intel r1304sposhorr bios -
    intel r1304sposhorr -
    intel r1208sposhorr bios -
    intel r1208sposhorr -
    intel lr1304spcfg1r bios -
    intel lr1304spcfg1r -
    intel r1208sposhor bios -
    intel r1208sposhor -
    intel s1200spsr bios -
    intel s1200spsr -
    intel s1200spor bios -
    intel s1200spor -
    intel lr1304spcfg1 bios -
    intel lr1304spcfg1 -
    intel s1200spl bios -
    intel s1200spl -
    intel s1200spo bios -
    intel s1200spo -
    intel s1200sps bios -
    intel s1200sps -
    intel r1304sposhbn bios -
    intel r1304sposhbn -
    intel s1200splr bios -
    intel s1200splr -
    intel r1304sposhbnr bios -
    intel r1304sposhbnr -
    lenovo thinkcentre m6600 -
    lenovo thinkpad t460 -
    lenovo thinkpad t460p -
    lenovo thinkpad t460s -