« Volver al listado

CVE-2017-5699

Estado: ModificadaMedia (5.5)—

Error de validación de entradas en Intel MinnowBoard 3 con versiones de firmware anteriores a la 0.65 permiten que un atacante local provoque una denegación de servicio mediante API UEFI.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-5699",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.1,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": true,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@intel.com",
      "affectedData": [
        {
          "vendor": "Intel Corporation",
          "product": "MinnowBoard 3",
          "versions": [
            {
              "status": "affected",
              "version": "before 0.65"
            }
          ]
        }
      ]
    }
  ],
  "published": "2018-01-18T02:29:17.210",
  "references": [
    {
      "url": "https://edk2-docs.gitbooks.io/security-advisory/content/uefi-variable-deletioncorruption.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "secure@intel.com"
    },
    {
      "url": "https://edk2-docs.gitbooks.io/security-advisory/content/uefi-variable-deletioncorruption.html",
      "tags": [
        "Patch",
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Input validation error in Intel MinnowBoard 3 Firmware versions prior to 0.65 allow local attacker to cause denial of service via UEFI APIs."
    },
    {
      "lang": "es",
      "value": "Error de validación de entradas en Intel MinnowBoard 3 con versiones de firmware anteriores a la 0.65 permiten que un atacante local provoque una denegación de servicio mediante API UEFI."
    }
  ],
  "lastModified": "2026-06-17T01:21:03.917",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:intel:minnowboard_3_firmware:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6558913C-5D12-4BC1-A91D-06BA219D0CD1",
              "versionEndExcluding": "0.65"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:intel:minnowboard_3:-:*:*:*:*:*:*:*",
              "vulnerable": false,
              "matchCriteriaId": "DA1ED7B0-6ADC-4E7E-942B-9D2D50E1EF14"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "secure@intel.com"
}