Vulnerabilities > Intel > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-01-18 CVE-2017-5699 Improper Input Validation vulnerability in Intel Minnowboard 3 Firmware
Input validation error in Intel MinnowBoard 3 Firmware versions prior to 0.65 allow local attacker to cause denial of service via UEFI APIs.
local
low complexity
intel CWE-20
5.5
2018-01-09 CVE-2018-3610 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Intel Driver & Support Assistant
SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and writing to Memory Status registers potentially allowing information disclosure or a denial of service condition.
local
low complexity
intel CWE-119
6.0
2018-01-04 CVE-2017-5754 Information Exposure vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
local
high complexity
intel arm CWE-200
5.6
2018-01-04 CVE-2017-5753 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
5.6
2018-01-04 CVE-2017-5715 Information Exposure Through Discrepancy vulnerability in multiple products
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
5.6
2017-09-05 CVE-2017-5698 Unspecified vulnerability in Intel products
Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative privileges.
local
low complexity
intel
4.4
2017-08-09 CVE-2017-5695 Improper Input Validation vulnerability in Intel products
Data corruption vulnerability in firmware in Intel Solid-State Drive Consumer, Professional, Embedded, Data Center affected firmware versions LSBG200, LSF031C, LSF036C, LBF010C, LSBG100, LSF031C, LSF036C, LBF010C, LSF031P, LSF036P, LBF010P, LSF031P, LSF036P, LBF010P, LSMG200, LSF031E, LSF036E, LSMG100, LSF031E, LSF036E, LSDG200, LSF031D, LSF036D allows local users to cause a denial of service via unspecified vectors.
low complexity
intel CWE-20
4.6
2017-08-09 CVE-2017-5694 Unspecified vulnerability in Intel SSD PRO 6000P Firmware Psf104P/Psf109P
Data corruption vulnerability in firmware in Intel Solid-State Drive Professional PSF104P, PSF109P allows local users to cause a denial of service via unspecified vectors.
low complexity
intel
4.6
2017-06-14 CVE-2017-5697 Improper Restriction of Rendered UI Layers or Frames vulnerability in Intel Active Management Technology Firmware
Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.
network
low complexity
intel CWE-1021
6.5
2017-05-31 CVE-2017-5688 Unspecified vulnerability in Intel Solid State Drive Toolbox 3.4.3
There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code.
local
low complexity
intel
6.7