CVE-2017-5703

Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially leading to a Denial of Service.

Published: 2018-04-03 Last update: 2024-11-21 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2017-5703 is rated Low Risk (34.2/100): CVSS Medium severity, with low exploitation likelihood (EPSS 0.12%). Mandatory action: Monitor for updates and reassess as exploit intelligence or EPSS changes.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Exploit prediction scoring system (EPSS) score for CVE-2017-5703

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2025-03-17 0.04% 0.12% +0.08%
2 2023-03-07 0.95% 0.04% -0.91%
3 2022-02-04 0.95%

Full EPSS history (4 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2017-5703

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
6.0 3.0 MEDIUM
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H Click to expand
Attack vector (AV:L)
They already need access on the box, or another person has to do something wrong; it’s not a remote drive-by.
Attack complexity (AC:L)
Once they can reach the bug, pulling it off is straightforward—no weird race conditions or rare setup.
Privileges required (PR:H)
They need powerful rights—admin, root, or similar—before this pays off.
User interaction (UI:N)
Nobody has to click “OK” or open a trap file; it can work without a victim helping.
Scope (S:C)
Breaking this can reach past the original component and bite other resources—bigger blast radius.
Confidentiality (C:N)
Doesn’t really leak secrets in a meaningful way.
Integrity (I:N)
Data isn’t meaningfully altered or forged.
Availability (A:H)
Could take the service down hard or make it unusable for people who depend on it.
1.5 4.0 [email protected]
3.6 2.0 LOW
AV:L/AC:L/Au:N/C:N/I:P/A:P Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:N)
No confidentiality impact.
Integrity impact (I:P)
Partial integrity impact.
Availability impact (A:P)
Partial availability impact.
3.9 4.9 [email protected]

Weakness enumeration for CVE-2017-5703

Affected software / configurations for CVE-2017-5703

Vendor Product Version Raw CPE
intel core_i7-8550u cpe:2.3:a:intel:core_i7-8550u:-:*:*:*:*:*:*:*
intel core_i7-8559u cpe:2.3:a:intel:core_i7-8559u:-:*:*:*:*:*:*:*
intel core_i7-8650u cpe:2.3:a:intel:core_i7-8650u:-:*:*:*:*:*:*:*
intel core_i7-8700 cpe:2.3:a:intel:core_i7-8700:-:*:*:*:*:*:*:*
intel core_i7-8700b cpe:2.3:a:intel:core_i7-8700b:-:*:*:*:*:*:*:*
intel core_i7-8700k cpe:2.3:a:intel:core_i7-8700k:-:*:*:*:*:*:*:*
intel core_i7-8700t cpe:2.3:a:intel:core_i7-8700t:-:*:*:*:*:*:*:*
intel core_i7-8705g cpe:2.3:a:intel:core_i7-8705g:-:*:*:*:*:*:*:*
intel core_i7-8706g cpe:2.3:a:intel:core_i7-8706g:-:*:*:*:*:*:*:*
intel core_i7-8709g cpe:2.3:a:intel:core_i7-8709g:-:*:*:*:*:*:*:*
intel core_i7-8750h cpe:2.3:a:intel:core_i7-8750h:-:*:*:*:*:*:*:*
intel core_i7-8809g cpe:2.3:a:intel:core_i7-8809g:-:*:*:*:*:*:*:*
intel core_i7-8850h cpe:2.3:a:intel:core_i7-8850h:-:*:*:*:*:*:*:*
intel core_i7-7500u cpe:2.3:a:intel:core_i7-7500u:-:*:*:*:*:*:*:*
intel core_i7-7560u cpe:2.3:a:intel:core_i7-7560u:-:*:*:*:*:*:*:*
intel core_i7-7567u cpe:2.3:a:intel:core_i7-7567u:-:*:*:*:*:*:*:*
intel core_i7-7600u cpe:2.3:a:intel:core_i7-7600u:-:*:*:*:*:*:*:*
intel core_i7-7660u cpe:2.3:a:intel:core_i7-7660u:-:*:*:*:*:*:*:*
intel core_i7-7700 cpe:2.3:a:intel:core_i7-7700:-:*:*:*:*:*:*:*
intel core_i7-7700hq cpe:2.3:a:intel:core_i7-7700hq:-:*:*:*:*:*:*:*
intel core_i7-7700k cpe:2.3:a:intel:core_i7-7700k:-:*:*:*:*:*:*:*
intel core_i7-7700t cpe:2.3:a:intel:core_i7-7700t:-:*:*:*:*:*:*:*
intel core_i7-7820eq cpe:2.3:a:intel:core_i7-7820eq:-:*:*:*:*:*:*:*
intel core_i7-7820hk cpe:2.3:a:intel:core_i7-7820hk:-:*:*:*:*:*:*:*
intel core_i7-7820hq cpe:2.3:a:intel:core_i7-7820hq:-:*:*:*:*:*:*:*
intel core_i7-7920hq cpe:2.3:a:intel:core_i7-7920hq:-:*:*:*:*:*:*:*
intel core_i7-7y75 cpe:2.3:a:intel:core_i7-7y75:-:*:*:*:*:*:*:*
intel core_i7-6500u cpe:2.3:a:intel:core_i7-6500u:-:*:*:*:*:*:*:*
intel core_i7-6560u cpe:2.3:a:intel:core_i7-6560u:-:*:*:*:*:*:*:*
intel core_i7-6567u cpe:2.3:a:intel:core_i7-6567u:-:*:*:*:*:*:*:*
intel core_i7-6600u cpe:2.3:a:intel:core_i7-6600u:-:*:*:*:*:*:*:*
intel core_i7-6650u cpe:2.3:a:intel:core_i7-6650u:-:*:*:*:*:*:*:*
intel core_i7-6660u cpe:2.3:a:intel:core_i7-6660u:-:*:*:*:*:*:*:*
intel core_i7-6700 cpe:2.3:a:intel:core_i7-6700:-:*:*:*:*:*:*:*
intel core_i7-6700hq cpe:2.3:a:intel:core_i7-6700hq:-:*:*:*:*:*:*:*
intel core_i7-6700k cpe:2.3:a:intel:core_i7-6700k:-:*:*:*:*:*:*:*
intel core_i7-6700t cpe:2.3:a:intel:core_i7-6700t:-:*:*:*:*:*:*:*
intel core_i7-6700te cpe:2.3:a:intel:core_i7-6700te:-:*:*:*:*:*:*:*
intel core_i7-6770hq cpe:2.3:a:intel:core_i7-6770hq:-:*:*:*:*:*:*:*
intel core_i7-6785r cpe:2.3:a:intel:core_i7-6785r:-:*:*:*:*:*:*:*
intel core_i7-6820eq cpe:2.3:a:intel:core_i7-6820eq:-:*:*:*:*:*:*:*
intel core_i7-6820hk cpe:2.3:a:intel:core_i7-6820hk:-:*:*:*:*:*:*:*
intel core_i7-6820hq cpe:2.3:a:intel:core_i7-6820hq:-:*:*:*:*:*:*:*
intel core_i7-6822eq cpe:2.3:a:intel:core_i7-6822eq:-:*:*:*:*:*:*:*
intel core_i7-6870hq cpe:2.3:a:intel:core_i7-6870hq:-:*:*:*:*:*:*:*
intel core_i7-6920hq cpe:2.3:a:intel:core_i7-6920hq:-:*:*:*:*:*:*:*
intel core_i7-6970hq cpe:2.3:a:intel:core_i7-6970hq:-:*:*:*:*:*:*:*
intel core_i7-5500u cpe:2.3:a:intel:core_i7-5500u:-:*:*:*:*:*:*:*
intel core_i7-5550u cpe:2.3:a:intel:core_i7-5550u:-:*:*:*:*:*:*:*
intel core_i7-5557u cpe:2.3:a:intel:core_i7-5557u:-:*:*:*:*:*:*:*
intel core_i7-5600u cpe:2.3:a:intel:core_i7-5600u:-:*:*:*:*:*:*:*
intel core_i7-5650u cpe:2.3:a:intel:core_i7-5650u:-:*:*:*:*:*:*:*
intel core_i7-5700eq cpe:2.3:a:intel:core_i7-5700eq:-:*:*:*:*:*:*:*
intel core_i7-5700hq cpe:2.3:a:intel:core_i7-5700hq:-:*:*:*:*:*:*:*
intel core_i7-5750hq cpe:2.3:a:intel:core_i7-5750hq:-:*:*:*:*:*:*:*
intel core_i7-5775c cpe:2.3:a:intel:core_i7-5775c:-:*:*:*:*:*:*:*
intel core_i7-5775r cpe:2.3:a:intel:core_i7-5775r:-:*:*:*:*:*:*:*
intel core_i7-5850eq cpe:2.3:a:intel:core_i7-5850eq:-:*:*:*:*:*:*:*
intel core_i7-5850hq cpe:2.3:a:intel:core_i7-5850hq:-:*:*:*:*:*:*:*
intel core_i7-5950hq cpe:2.3:a:intel:core_i7-5950hq:-:*:*:*:*:*:*:*
intel celeron_n2805 cpe:2.3:a:intel:celeron_n2805:-:*:*:*:*:*:*:*
intel celeron_n2806 cpe:2.3:a:intel:celeron_n2806:-:*:*:*:*:*:*:*
intel celeron_n2807 cpe:2.3:a:intel:celeron_n2807:-:*:*:*:*:*:*:*
intel celeron_n2808 cpe:2.3:a:intel:celeron_n2808:-:*:*:*:*:*:*:*
intel celeron_n2810 cpe:2.3:a:intel:celeron_n2810:-:*:*:*:*:*:*:*
intel celeron_n2815 cpe:2.3:a:intel:celeron_n2815:-:*:*:*:*:*:*:*
intel celeron_n2820 cpe:2.3:a:intel:celeron_n2820:-:*:*:*:*:*:*:*
intel celeron_n2830 cpe:2.3:a:intel:celeron_n2830:-:*:*:*:*:*:*:*
intel celeron_n2840 cpe:2.3:a:intel:celeron_n2840:-:*:*:*:*:*:*:*
intel celeron_n2920 cpe:2.3:a:intel:celeron_n2920:-:*:*:*:*:*:*:*
intel celeron_n3520 cpe:2.3:a:intel:celeron_n3520:-:*:*:*:*:*:*:*
intel pentium_n3520 cpe:2.3:a:intel:pentium_n3520:-:*:*:*:*:*:*:*
intel atom_x5-e3930 cpe:2.3:a:intel:atom_x5-e3930:-:*:*:*:*:*:*:*
intel atom_x5-e3940 cpe:2.3:a:intel:atom_x5-e3940:-:*:*:*:*:*:*:*
intel atom_x5-e8000 cpe:2.3:a:intel:atom_x5-e8000:-:*:*:*:*:*:*:*
intel atom_x5-z8300 cpe:2.3:a:intel:atom_x5-z8300:-:*:*:*:*:*:*:*
intel atom_x5-z8330 cpe:2.3:a:intel:atom_x5-z8330:-:*:*:*:*:*:*:*
intel atom_x5-z8350 cpe:2.3:a:intel:atom_x5-z8350:-:*:*:*:*:*:*:*
intel atom_x5-z8500 cpe:2.3:a:intel:atom_x5-z8500:-:*:*:*:*:*:*:*
intel atom_x5-z8550 cpe:2.3:a:intel:atom_x5-z8550:-:*:*:*:*:*:*:*

References for CVE-2017-5703

cvelogic Threat Intelligence