MEDIUM · 6.7

CVE-2016-8103

SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.

Vulnerability Description

SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.

CVSS Score

6.7

MEDIUM

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
IntelCity Bios<= ccsklm5v.86a
IntelStk2M3W64Cc-
IntelCanyon Bios<= kyskli70.86a
IntelNuc6I7Kyb-
IntelNuc5Cpyh-
IntelNuc5Pgyh-
IntelNuc5Ppyh-
IntelStk2Mv64Cc-
IntelDn2820Fyb-
IntelSwift Canyon Bios<= syskli35.86a
IntelNuc6I3Syb-
IntelNuc6I5Syb-
IntelCitry Bios<= scchtax5.86a
IntelStk1Aw32Sc-
IntelNuc5I3Mybe-
IntelStk1A32Sc-
IntelNuc5I3Ryb-
IntelNuc5I5Ryb-
IntelNuc5I7Rykh-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2016-8103?

CVE-2016-8103 is a vulnerability with a CVSS score of 6.7 (MEDIUM). SMM call out in all Intel Branded NUC Kits allows a local privileged user to access the System Management Mode and take full control of the platform.

How severe is CVE-2016-8103?

CVE-2016-8103 has been rated MEDIUM with a CVSS base score of 6.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2016-8103?

Check the references section above for vendor advisories and patch information. Affected products include: Intel City Bios, Intel Stk2M3W64Cc, Intel Canyon Bios, Intel Nuc6I7Kyb, Intel Nuc5Cpyh.