First published: Wed Jul 26 2017(Updated: )
Incorrect check in Intel processors from 6th and 7th Generation Intel Core Processor Families, Intel Xeon E3-1500M v5 and v6 Product Families, and Intel Xeon E3-1200 v5 and v6 Product Families allows compromised system firmware to impact SGX security via incorrect early system state.
Credit: secure@intel.com
Affected Software | Affected Version | How to fix |
---|---|---|
Intel NUC mini pc NUC7i3BNK | ||
Intel NUC kit nuc7i3bnk | ||
Intel NUC 7i5BNK BIOS | ||
Intel NUC 7i5-BNK | ||
Intel NUC 7i7BNH BIOS | ||
Intel NUC NUC7i7BNH | ||
Intel STK2M3W64CC BIOS | ||
Intel Compute Stick STK2MV64CC | ||
Intel STK2M3W64CC BIOS | ||
Intel Compute Stick STK2M3W64CC Firmware | ||
Intel NUC 6i7KYK BIOS | ||
Intel NUC6i7KYK Firmware | ||
Intel NUC 6i5SYK BIOS | ||
Intel NUC Kit NUC6i3SYK | ||
Intel NUC 6i5SYK BIOS | ||
Intel NUC 6i5SYK BIOS | ||
Intel R1304SPOSHOR | ||
Intel Server System R1304SPOSHOR | ||
Intel R1304SPOSHORR | ||
Intel Server System R1304SPOSHORR | ||
Intel R1208SPOSHORR | ||
Intel R1208SPOSHORR BIOS | ||
Intel lr1304spcfg1r | ||
Intel Server System LR1304SPCFG1R | ||
Intel R1208SPOSHORR | ||
Intel R1208SPOSHOR BIOS | ||
Intel S1200SPSR | ||
Intel Server Board S1200SPSR | ||
Intel S1200SPOR | ||
Intel Server Board S1200SPOR | ||
Intel LR1304SPCFGR1 BIOS | ||
Intel lr1304spcfg1r | ||
Intel S1200SPL | ||
Intel S1200SPL BIOS | ||
Intel S1200SP | ||
Intel S1200SP0 BIOS | ||
Intel S1200SPS | ||
Intel Server Board S1200SPS | ||
Intel R1304SPOSHBNR BIOS | ||
Intel Server System R1304SPOSHB | ||
Intel S1200SPLR | ||
Intel Server Board S1200SPLR | ||
Intel R1304SPOSHBNR BIOS | ||
Intel Server System R1304SPOSHBnR |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-5691 is classified as a medium severity vulnerability affecting certain Intel processors.
To mitigate CVE-2017-5691, you should update the affected system firmware to the latest version provided by Intel.
CVE-2017-5691 affects the 6th and 7th Generation Intel Core Processor Families as well as certain Intel Xeon E3 product families.
The impact of CVE-2017-5691 includes the potential compromise of SGX security due to incorrect early system state checks.
Yes, CVE-2017-5691 specifically affects systems with certain BIOS versions associated with the vulnerable Intel processors.