CVE-2016-8103
6.7
Vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.
Affected (12)
Products: Intel: City Bios, Canyon Bios, Swift Canyon Bios, Citry Bios
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Up to kyskli70.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc6i7kyb | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to pybwcel.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc5cpyh | All versions |
Intel Nuc5pgyh | All versions |
Intel Nuc5ppyh | All versions |
Configuration D
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to fybyt10h.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Dn2820fyb | All versions |
Configuration F
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to syskli35.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc6i3syb | All versions |
Intel Nuc6i5syb | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to scchtax5.86a |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to mybdwi5v.86a |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to mybdwi30.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc5i3mybe | All versions |
Configuration K
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to rybdwi35.86a |
| Running on/with | Platform Versions |
|---|---|
Intel Nuc5i3ryb | All versions |
Intel Nuc5i5ryb | All versions |
Intel Nuc5i7rykh | All versions |
Related CWEs
References (4)
Source: secure@intel.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.