Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-5721


Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to execute arbitrary code via manipulation of memory.


Security Impact Summary

This vulnerability carries a HIGH severity rating with a CVSS v3.1 score of 7.5, requiring local system access to exploit but requires specific conditions to be met without requiring user interaction . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 10 products from intel, from intel, from intel and 7 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

First disclosed in 2017, this vulnerability was reported during a period defined by widespread IoT adoption challenges, mobile security concerns, and the emergence of advanced persistent threat (APT) techniques. Contemporary mitigation strategies focused on secure development practices and third-party component vetting.


Published

2017-10-11T00:29:00.303

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:L/AC:M/Au:N/C:P/I:P/A:P

  • Access Vector: LOCAL
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

3.4

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System intel nuc7i7bnh_firmware ayaplcel.86a.0041 Yes
Operating System intel nuc7i7bnh_firmware bnkbl357.86a.0052 Yes
Operating System intel nuc7i7bnh_firmware ccsklm5v.86a.0052 Yes
Operating System intel nuc7i7bnh_firmware ccsklm30.86a.0052 Yes
Operating System intel nuc7i7bnh_firmware dnkbli5v.86a.0026 Yes
Operating System intel nuc7i7bnh_firmware dnkbli30.86a.0026 Yes
Operating System intel nuc7i7bnh_firmware kyskli70.86a.0050 Yes
Operating System intel nuc7i7bnh_firmware rybdwi35.86a.0366 Yes
Operating System intel nuc7i7bnh_firmware syskli35.86a.0062 Yes
Operating System intel nuc7i7bnh_firmware tybyt20h.86a.0015 Yes
Hardware intel nuc7i7bnh - No
Operating System intel nuc7i5bnh_firmware ayaplcel.86a.0041 Yes
Operating System intel nuc7i5bnh_firmware bnkbl357.86a.0052 Yes
Operating System intel nuc7i5bnh_firmware ccsklm5v.86a.0052 Yes
Operating System intel nuc7i5bnh_firmware ccsklm30.86a.0052 Yes
Operating System intel nuc7i5bnh_firmware dnkbli5v.86a.0026 Yes
Operating System intel nuc7i5bnh_firmware dnkbli30.86a.0026 Yes
Operating System intel nuc7i5bnh_firmware kyskli70.86a.0050 Yes
Operating System intel nuc7i5bnh_firmware rybdwi35.86a.0366 Yes
Operating System intel nuc7i5bnh_firmware syskli35.86a.0062 Yes
Operating System intel nuc7i5bnh_firmware tybyt20h.86a.0015 Yes
Hardware intel nuc7i5bnh - No
Operating System intel nuc7i5bnk_firmware ayaplcel.86a.0041 Yes
Operating System intel nuc7i5bnk_firmware bnkbl357.86a.0052 Yes
Operating System intel nuc7i5bnk_firmware ccsklm5v.86a.0052 Yes
Operating System intel nuc7i5bnk_firmware ccsklm30.86a.0052 Yes
Operating System intel nuc7i5bnk_firmware dnkbli5v.86a.0026 Yes
Operating System intel nuc7i5bnk_firmware dnkbli30.86a.0026 Yes
Operating System intel nuc7i5bnk_firmware kyskli70.86a.0050 Yes
Operating System intel nuc7i5bnk_firmware rybdwi35.86a.0366 Yes
Operating System intel nuc7i5bnk_firmware syskli35.86a.0062 Yes
Operating System intel nuc7i5bnk_firmware tybyt20h.86a.0015 Yes
Hardware intel nuc7i5bnk - No
Operating System intel nuc7i3bnh_firmware ayaplcel.86a.0041 Yes
Operating System intel nuc7i3bnh_firmware bnkbl357.86a.0052 Yes
Operating System intel nuc7i3bnh_firmware ccsklm5v.86a.0052 Yes
Operating System intel nuc7i3bnh_firmware ccsklm30.86a.0052 Yes
Operating System intel nuc7i3bnh_firmware dnkbli5v.86a.0026 Yes
Operating System intel nuc7i3bnh_firmware dnkbli30.86a.0026 Yes
Operating System intel nuc7i3bnh_firmware kyskli70.86a.0050 Yes
Operating System intel nuc7i3bnh_firmware rybdwi35.86a.0366 Yes
Operating System intel nuc7i3bnh_firmware syskli35.86a.0062 Yes
Operating System intel nuc7i3bnh_firmware tybyt20h.86a.0015 Yes
Hardware intel nuc7i3bnh - No
Operating System intel nuc7i3bnk_firmware ayaplcel.86a.0041 Yes
Operating System intel nuc7i3bnk_firmware bnkbl357.86a.0052 Yes
Operating System intel nuc7i3bnk_firmware ccsklm5v.86a.0052 Yes
Operating System intel nuc7i3bnk_firmware ccsklm30.86a.0052 Yes
Operating System intel nuc7i3bnk_firmware dnkbli5v.86a.0026 Yes
Operating System intel nuc7i3bnk_firmware dnkbli30.86a.0026 Yes
Operating System intel nuc7i3bnk_firmware kyskli70.86a.0050 Yes
Operating System intel nuc7i3bnk_firmware rybdwi35.86a.0366 Yes
Operating System intel nuc7i3bnk_firmware syskli35.86a.0062 Yes
Operating System intel nuc7i3bnk_firmware tybyt20h.86a.0015 Yes
Hardware intel nuc7i3bnk - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For intel's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.