Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-8103


SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.


Published

2016-12-08T17:59:01.583

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:S/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.1

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System intel city_bios ≤ ccsklm5v.86a Yes
Hardware intel stk2m3w64cc - No
Operating System intel canyon_bios ≤ kyskli70.86a Yes
Hardware intel nuc6i7kyb - No
Operating System intel canyon_bios ≤ pybwcel.86a Yes
Hardware intel nuc5cpyh - No
Hardware intel nuc5pgyh - No
Hardware intel nuc5ppyh - No
Operating System intel city_bios ccsklm30.86a Yes
Hardware intel stk2mv64cc - No
Operating System intel canyon_bios ≤ fybyt10h.86a Yes
Hardware intel dn2820fyb - No
Operating System intel city_bios ≤ ccsklm30.86a Yes
Hardware intel stk2m3w64cc - No
Operating System intel swift_canyon_bios ≤ syskli35.86a Yes
Hardware intel nuc6i3syb - No
Hardware intel nuc6i5syb - No
Operating System intel citry_bios ≤ scchtax5.86a Yes
Hardware intel stk1aw32sc - No
Operating System intel canyon_bios ≤ mybdwi5v.86a Yes
Hardware intel nuc5i3mybe - No
Operating System intel canyon_bios ≤ mybdwi30.86a Yes
Hardware intel nuc5i3mybe - No
Operating System intel city_bios ≤ scchtax5.86a Yes
Hardware intel stk1a32sc - No
Hardware intel stk1aw32sc - No
Operating System intel canyon_bios ≤ rybdwi35.86a Yes
Hardware intel nuc5i3ryb - No
Hardware intel nuc5i5ryb - No
Hardware intel nuc5i7rykh - No

References