製品・ソフトウェアに関する情報
Intel Branded NUC キットにおけるシステムマネジメントモードにアクセスされる脆弱性
Title Intel Branded NUC キットにおけるシステムマネジメントモードにアクセスされる脆弱性
Summary

Intel Branded NUC キットには、システムマネジメントモードにアクセスされ、プラットフォームを完全に制御される脆弱性が存在します。

Possible impacts ローカル権限のユーザにより、システムマネジメントモードにアクセスされ、プラットフォームを完全に制御される可能性があります。
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date Oct. 3, 2016, midnight
Registration Date Dec. 14, 2016, 12:24 p.m.
Last Update Dec. 14, 2016, 12:24 p.m.
CVSS3.0 : 警告
Score 6.7
Vector CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS2.0 : 警告
Score 6.8
Vector AV:L/AC:L/Au:S/C:C/I:C/A:C
Affected System
インテル
Canyon BIOS 
City BIOS 
Intel Compute Stick STK1A32SC (Sterling City SCCHTAX5.86A)
Intel Compute Stick STK1AW32SC (Sterlig Citry SCCHTAX5.86a)
Intel Compute Stick STK1AW32SC (Sterling City SCCHTAX5.86A)
Intel Compute Stick STK2m3w64CC (Cedar City - m3 CCSKLm30.86A)
Intel Compute Stick STK2m3w64CC (Cedar City - m5 CCSKLm5v.86A)
Intel Compute Stick STK2mv64CC (Cedar City - m3 CCSKLm30.86a)
Intel NUC Kit DN2820FYB (Forest Canyon FYBYT10H.86a)
Intel NUC Kit NUC5CPYH (Pinnacle Canyon - Celeron PYBWCEL.86A)
Intel NUC Kit NUC5i3MYBE (Maple Canyon - i3 MYBDWi30.86A)
Intel NUC Kit NUC5i3MYBE (Maple Canyon - i5 MYBDWi5v.86A)
Intel NUC Kit NUC5i3RYB (Rock Canyon - i3 RYBDWi35.86A)
Intel NUC Kit NUC5i5RYB (Rock Canyon - i5 RYBDWi35.86A)
Intel NUC Kit NUC5i7RYKH (Rock Canyon - i7 RYBDWi35.86A)
Intel NUC Kit NUC5PGYH (Grass Canyon - Pentium PYBWCEL.86A)
Intel NUC Kit NUC5PPYH (Pinnacle Canyon - Pentium PYBWCEL.86A)
Intel NUC Kit NUC6i3SYB (Swift Canyon - i3 SYSKLi35.86A)
Intel NUC Kit NUC6i5SYB (Swift Canyon - i5 SYSKLi35.86A)
Intel NUC Kit NUC6i7KYB (Skull Canyon - i7 KYSKLi70.86A)
Swift Canyon BIOS 
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
Change Log
No Changed Details Date of change
0 [2016年12月14日]
  掲載
Feb. 17, 2018, 10:37 a.m.

NVD Vulnerability Information
CVE-2016-8103
Summary

SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.

Publication Date Dec. 9, 2016, 2:59 a.m.
Registration Date Jan. 26, 2021, 2:18 p.m.
Last Update Nov. 21, 2024, 11:58 a.m.
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:intel:city_bios:*:*:*:*:*:*:*:* ccsklm5v.86a
execution environment
1 cpe:2.3:h:intel:stk2m3w64cc:-:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:o:intel:canyon_bios:*:*:*:*:*:*:*:* kyskli70.86a
execution environment
1 cpe:2.3:h:intel:nuc6i7kyb:-:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:intel:canyon_bios:*:*:*:*:*:*:*:* pybwcel.86a
execution environment
1 cpe:2.3:h:intel:nuc5cpyh:-:*:*:*:*:*:*:*
2 cpe:2.3:h:intel:nuc5pgyh:-:*:*:*:*:*:*:*
3 cpe:2.3:h:intel:nuc5ppyh:-:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:o:intel:city_bios:ccsklm30.86a:*:*:*:*:*:*:*
execution environment
1 cpe:2.3:h:intel:stk2mv64cc:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:o:intel:canyon_bios:*:*:*:*:*:*:*:* fybyt10h.86a
execution environment
1 cpe:2.3:h:intel:dn2820fyb:-:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:o:intel:city_bios:*:*:*:*:*:*:*:* ccsklm30.86a
execution environment
1 cpe:2.3:h:intel:stk2m3w64cc:-:*:*:*:*:*:*:*
Configuration7 or higher or less more than less than
cpe:2.3:o:intel:swift_canyon_bios:*:*:*:*:*:*:*:* syskli35.86a
execution environment
1 cpe:2.3:h:intel:nuc6i3syb:-:*:*:*:*:*:*:*
2 cpe:2.3:h:intel:nuc6i5syb:-:*:*:*:*:*:*:*
Configuration8 or higher or less more than less than
cpe:2.3:o:intel:citry_bios:*:*:*:*:*:*:*:* scchtax5.86a
execution environment
1 cpe:2.3:h:intel:stk1aw32sc:-:*:*:*:*:*:*:*
Configuration9 or higher or less more than less than
cpe:2.3:o:intel:canyon_bios:*:*:*:*:*:*:*:* mybdwi5v.86a
execution environment
1 cpe:2.3:h:intel:nuc5i3mybe:-:*:*:*:*:*:*:*
Configuration10 or higher or less more than less than
cpe:2.3:o:intel:canyon_bios:*:*:*:*:*:*:*:* mybdwi30.86a
execution environment
1 cpe:2.3:h:intel:nuc5i3mybe:-:*:*:*:*:*:*:*
Configuration11 or higher or less more than less than
cpe:2.3:o:intel:city_bios:*:*:*:*:*:*:*:* scchtax5.86a
execution environment
1 cpe:2.3:h:intel:stk1a32sc:-:*:*:*:*:*:*:*
2 cpe:2.3:h:intel:stk1aw32sc:-:*:*:*:*:*:*:*
Configuration12 or higher or less more than less than
cpe:2.3:o:intel:canyon_bios:*:*:*:*:*:*:*:* rybdwi35.86a
execution environment
1 cpe:2.3:h:intel:nuc5i3ryb:-:*:*:*:*:*:*:*
2 cpe:2.3:h:intel:nuc5i5ryb:-:*:*:*:*:*:*:*
3 cpe:2.3:h:intel:nuc5i7rykh:-:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List