ID

VAR-201610-0228


CVE

CVE-2016-8101


TITLE

Intel SSD Toolbox of updater Subsystem vulnerability

Trust: 0.8

sources: JVNDB: JVNDB-2016-005374

DESCRIPTION

The updater subsystem in Intel SSD Toolbox before 3.3.7 allows local users to gain privileges via unspecified vectors. Attackers can exploit this issue to gain elevated privileges within the context of the operating system. Intel SSD Toolbox 3.1.0 through 3.3.6 are vulnerable

Trust: 1.98

sources: NVD: CVE-2016-8101 // JVNDB: JVNDB-2016-005374 // BID: 93482 // VULHUB: VHN-96921

AFFECTED PRODUCTS

vendor:intelmodel:solid-state drive toolboxscope:lteversion:3.3.6

Trust: 1.0

vendor:intelmodel:ssd toolboxscope:ltversion:3.3.7

Trust: 0.8

vendor:intelmodel:solid-state drive toolboxscope:eqversion:3.3.6

Trust: 0.6

vendor:intelmodel:solid state drive toolboxscope:eqversion:3.3.6

Trust: 0.3

vendor:intelmodel:solid state drive toolboxscope:eqversion:3.3.5

Trust: 0.3

vendor:intelmodel:solid state drive toolboxscope:eqversion:3.3.2

Trust: 0.3

vendor:intelmodel:solid state drive toolboxscope:eqversion:3.3.1

Trust: 0.3

vendor:intelmodel:solid state drive toolboxscope:eqversion:3.3

Trust: 0.3

vendor:intelmodel:solid state drive toolboxscope:eqversion:3.2.1

Trust: 0.3

vendor:intelmodel:solid state drive toolboxscope:eqversion:3.1

Trust: 0.3

vendor:intelmodel:solid state drive toolboxscope:neversion:3.3.7

Trust: 0.3

sources: BID: 93482 // JVNDB: JVNDB-2016-005374 // CNNVD: CNNVD-201610-235 // NVD: CVE-2016-8101

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-8101
value: HIGH

Trust: 1.0

NVD: CVE-2016-8101
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201610-235
value: HIGH

Trust: 0.6

VULHUB: VHN-96921
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2016-8101
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-96921
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-8101
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-96921 // JVNDB: JVNDB-2016-005374 // CNNVD: CNNVD-201610-235 // NVD: CVE-2016-8101

PROBLEMTYPE DATA

problemtype:CWE-264

Trust: 1.9

sources: VULHUB: VHN-96921 // JVNDB: JVNDB-2016-005374 // NVD: CVE-2016-8101

THREAT TYPE

local

Trust: 0.9

sources: BID: 93482 // CNNVD: CNNVD-201610-235

TYPE

permissions and access control

Trust: 0.6

sources: CNNVD: CNNVD-201610-235

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-005374

PATCH

title:INTEL-SA-00061url:https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00061&languageid=en-fr

Trust: 0.8

title:Intel SSD Toolbox Security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=64634

Trust: 0.6

sources: JVNDB: JVNDB-2016-005374 // CNNVD: CNNVD-201610-235

EXTERNAL IDS

db:NVDid:CVE-2016-8101

Trust: 2.8

db:BIDid:93482

Trust: 1.4

db:JVNDBid:JVNDB-2016-005374

Trust: 0.8

db:CNNVDid:CNNVD-201610-235

Trust: 0.7

db:VULHUBid:VHN-96921

Trust: 0.1

sources: VULHUB: VHN-96921 // BID: 93482 // JVNDB: JVNDB-2016-005374 // CNNVD: CNNVD-201610-235 // NVD: CVE-2016-8101

REFERENCES

url:https://security-center.intel.com/advisory.aspx?intelid=intel-sa-00061&languageid=en-fr

Trust: 1.9

url:http://www.securityfocus.com/bid/93482

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-8101

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-8101

Trust: 0.8

url:http://www.intel.com/content/www/us/en/homepage.html

Trust: 0.3

url:http://www.intel.com/content/www/us/en/support/solid-state-drives/ssd-software/intel-ssd-toolbox.html

Trust: 0.3

url:https://security-center.intel.com/advisory.aspx?intelid=intel-sa-00061&languageid=en-fr

Trust: 0.1

sources: VULHUB: VHN-96921 // BID: 93482 // JVNDB: JVNDB-2016-005374 // CNNVD: CNNVD-201610-235 // NVD: CVE-2016-8101

CREDITS

Florian Bogner

Trust: 0.3

sources: BID: 93482

SOURCES

db:VULHUBid:VHN-96921
db:BIDid:93482
db:JVNDBid:JVNDB-2016-005374
db:CNNVDid:CNNVD-201610-235
db:NVDid:CVE-2016-8101

LAST UPDATE DATE

2025-04-13T23:32:37.080000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-96921date:2016-12-02T00:00:00
db:BIDid:93482date:2016-10-26T11:02:00
db:JVNDBid:JVNDB-2016-005374date:2016-10-19T00:00:00
db:CNNVDid:CNNVD-201610-235date:2016-10-11T00:00:00
db:NVDid:CVE-2016-8101date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-96921date:2016-10-10T00:00:00
db:BIDid:93482date:2016-10-04T00:00:00
db:JVNDBid:JVNDB-2016-005374date:2016-10-19T00:00:00
db:CNNVDid:CNNVD-201610-235date:2016-10-11T00:00:00
db:NVDid:CVE-2016-8101date:2016-10-10T16:59:04.730