10
CVE-2017-5689
- EPSS 94.3%
- Veröffentlicht 02.05.2017 14:59:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
- Quelle secure@intel.com
- Teams Watchlist Login
- Unerledigt Login
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hpe ≫ Proliant Ml10 Gen9 Server Firmware Version5.0
Siemens ≫ Simatic Itp1000 Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Ipc847d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Ipc847c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Ipc827d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Ipc827c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Ipc677d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Ipc677c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Ipc647d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Ipc647c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Ipc627d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Ipc627c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Ipc547g Firmware Version < 11.0.26.3000
Siemens ≫ Simatic Ipc547e Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Ipc547d Firmware Version < 7.1.91.3272
Siemens ≫ Simatic Ipc477e Firmware Version < 21.01.05
Siemens ≫ Simatic Ipc477d Firmware Version- SwEdition-
Siemens ≫ Simatic Ipc477d Firmware Version- SwEditionpro
Siemens ≫ Simatic Field Pg M3 Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Field Pg M4 Firmware Version < 18.01.06
Siemens ≫ Simatic Field Pg M5 Firmware Version < 22.01.03
Siemens ≫ Simatic Ipc627d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Ipc677d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Pcs 7 Ipc427e Firmware Version < 21.01.04
Siemens ≫ Simatic Pcs 7 Ipc547d Firmware Version < 7.1.91.3272
Siemens ≫ Simatic Pcs 7 Ipc547e Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Pcs 7 Ipc547g Firmware Version < 11.0.26.3000
Siemens ≫ Simatic Pcs 7 Ipc627c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Pcs 7 Ipc677c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Pcs 7 Ipc647c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Pcs 7 Ipc647d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Pcs 7 Ipc847c Firmware Version < 6.2.61.3535
Siemens ≫ Simatic Pcs 7 Ipc847d Firmware Version < 9.1.41.3024
Siemens ≫ Simatic Pcs 7 Ipc427e Firmware Version-
Siemens ≫ Simatic Pcs 7 Ipc547g Firmware Version < 11.0.26.3000
Siemens ≫ Simatic Pcs 7 Ipc477d Firmware Version-
Siemens ≫ Simatic Ipc427d Firmware Version-
Siemens ≫ Simatic Ipc427e Firmware Version < 21.01.05
Siemens ≫ Simotion P320-4 S Firmware Version < 17.02.06.83.1
Siemens ≫ Sinumerik Pcu50.5-p Firmware Version < 6.2.61.3535
Intel ≫ Active Management Technology Firmware Version6.0
Intel ≫ Active Management Technology Firmware Version6.1
Intel ≫ Active Management Technology Firmware Version6.2
Intel ≫ Active Management Technology Firmware Version7.0
Intel ≫ Active Management Technology Firmware Version7.1
Intel ≫ Active Management Technology Firmware Version8.0
Intel ≫ Active Management Technology Firmware Version8.1
Intel ≫ Active Management Technology Firmware Version9.0
Intel ≫ Active Management Technology Firmware Version9.1
Intel ≫ Active Management Technology Firmware Version9.5
Intel ≫ Active Management Technology Firmware Version10.0
Intel ≫ Active Management Technology Firmware Version11.0
Intel ≫ Active Management Technology Firmware Version11.5
Intel ≫ Active Management Technology Firmware Version11.6
28.01.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
SchwachstelleIntel products contain a vulnerability which can allow attackers to perform privilege escalation.
BeschreibungApply updates per vendor instructions.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 94.3% | 0.999 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.