CVE-2017-5700

high
Published 2017-10-11 ยท Modified 2026-05-13
CVSS v3
8.4
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
8.4

Description

Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.

Predictions

Exploit likelihood
80%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
intel intelnuc7i7bnh_firmwareayaplcel.86a.0041
intel intelnuc7i7bnh_firmwarebnkbl357.86a.0052
intel intelnuc7i7bnh_firmwareccsklm5v.86a.0052
intel intelnuc7i7bnh_firmwareccsklm30.86a.0052
intel intelnuc7i7bnh_firmwarednkbli5v.86a.0026
intel intelnuc7i7bnh_firmwarednkbli30.86a.0026
intel intelnuc7i7bnh_firmwarekyskli70.86a.0050
intel intelnuc7i7bnh_firmwarerybdwi35.86a.0366
intel intelnuc7i7bnh_firmwaresyskli35.86a.0062
intel intelnuc7i7bnh_firmwaretybyt20h.86a.0015
intel intelnuc7i7bnh-
intel intelnuc7i5bnh_firmwareayaplcel.86a.0041
intel intelnuc7i5bnh_firmwarebnkbl357.86a.0052
intel intelnuc7i5bnh_firmwareccsklm5v.86a.0052
intel intelnuc7i5bnh_firmwareccsklm30.86a.0052
intel intelnuc7i5bnh_firmwarednkbli5v.86a.0026
intel intelnuc7i5bnh_firmwarednkbli30.86a.0026
intel intelnuc7i5bnh_firmwarekyskli70.86a.0050
intel intelnuc7i5bnh_firmwarerybdwi35.86a.0366
intel intelnuc7i5bnh_firmwaresyskli35.86a.0062
intel intelnuc7i5bnh_firmwaretybyt20h.86a.0015
intel intelnuc7i5bnh-
intel intelnuc7i5bnk_firmwareayaplcel.86a.0041
intel intelnuc7i5bnk_firmwarebnkbl357.86a.0052
intel intelnuc7i5bnk_firmwareccsklm5v.86a.0052
intel intelnuc7i5bnk_firmwareccsklm30.86a.0052
intel intelnuc7i5bnk_firmwarednkbli5v.86a.0026
intel intelnuc7i5bnk_firmwarednkbli30.86a.0026
intel intelnuc7i5bnk_firmwarekyskli70.86a.0050
intel intelnuc7i5bnk_firmwarerybdwi35.86a.0366
intel intelnuc7i5bnk_firmwaresyskli35.86a.0062
intel intelnuc7i5bnk_firmwaretybyt20h.86a.0015
intel intelnuc7i5bnk-
intel intelnuc7i3bnh_firmwareayaplcel.86a.0041
intel intelnuc7i3bnh_firmwarebnkbl357.86a.0052
intel intelnuc7i3bnh_firmwareccsklm5v.86a.0052
intel intelnuc7i3bnh_firmwareccsklm30.86a.0052
intel intelnuc7i3bnh_firmwarednkbli5v.86a.0026
intel intelnuc7i3bnh_firmwarednkbli30.86a.0026
intel intelnuc7i3bnh_firmwarekyskli70.86a.0050
intel intelnuc7i3bnh_firmwarerybdwi35.86a.0366
intel intelnuc7i3bnh_firmwaresyskli35.86a.0062
intel intelnuc7i3bnh_firmwaretybyt20h.86a.0015
intel intelnuc7i3bnh-
intel intelnuc7i3bnk_firmwareayaplcel.86a.0041
intel intelnuc7i3bnk_firmwarebnkbl357.86a.0052
intel intelnuc7i3bnk_firmwareccsklm5v.86a.0052
intel intelnuc7i3bnk_firmwareccsklm30.86a.0052
intel intelnuc7i3bnk_firmwarednkbli5v.86a.0026
intel intelnuc7i3bnk_firmwarednkbli30.86a.0026
intel intelnuc7i3bnk_firmwarekyskli70.86a.0050
intel intelnuc7i3bnk_firmwarerybdwi35.86a.0366
intel intelnuc7i3bnk_firmwaresyskli35.86a.0062
intel intelnuc7i3bnk_firmwaretybyt20h.86a.0015
intel intelnuc7i3bnk-

References

CWEs

CWE-522

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.