10

CVE-2017-5689

Warnung
Exploit

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SiemensSimatic Itp1000 Firmware Version < 9.1.41.3024
   SiemensSimatic Itp1000 Version-
SiemensSimatic Ipc847d Firmware Version < 9.1.41.3024
   SiemensSimatic Ipc847d Version-
SiemensSimatic Ipc847c Firmware Version < 6.2.61.3535
   SiemensSimatic Ipc847c Version-
SiemensSimatic Ipc827d Firmware Version < 9.1.41.3024
   SiemensSimatic Ipc827d Version-
SiemensSimatic Ipc827c Firmware Version < 6.2.61.3535
   SiemensSimatic Ipc827c Version-
SiemensSimatic Ipc677d Firmware Version < 9.1.41.3024
   SiemensSimatic Ipc677d Version-
SiemensSimatic Ipc677c Firmware Version < 6.2.61.3535
   SiemensSimatic Ipc677c Version-
SiemensSimatic Ipc647d Firmware Version < 9.1.41.3024
   SiemensSimatic Ipc647d Version-
SiemensSimatic Ipc647c Firmware Version < 6.2.61.3535
   SiemensSimatic Ipc647c Version-
SiemensSimatic Ipc627d Firmware Version < 9.1.41.3024
   SiemensSimatic Ipc627d Version-
SiemensSimatic Ipc627c Firmware Version < 6.2.61.3535
   SiemensSimatic Ipc627c Version-
SiemensSimatic Ipc547g Firmware Version < 11.0.26.3000
   SiemensSimatic Ipc547g Version-
SiemensSimatic Ipc547e Firmware Version < 9.1.41.3024
   SiemensSimatic Ipc547e Version-
SiemensSimatic Ipc547d Firmware Version < 7.1.91.3272
   SiemensSimatic Ipc547d Version-
SiemensSimatic Ipc477e Firmware Version < 21.01.05
   SiemensSimatic Ipc477e Version-
SiemensSimatic Ipc477d Firmware Version- SwEdition-
   SiemensSimatic Ipc477d Version-
SiemensSimatic Ipc477d Firmware Version- SwEditionpro
   SiemensSimatic Ipc477d Version-
SiemensSimatic Field Pg M3 Firmware Version < 6.2.61.3535
   SiemensSimatic Field Pg M3 Version-
SiemensSimatic Field Pg M4 Firmware Version < 18.01.06
   SiemensSimatic Field Pg M4 Version-
SiemensSimatic Field Pg M5 Firmware Version < 22.01.03
   SiemensSimatic Field Pg M5 Version-
SiemensSimatic Ipc627d Firmware Version < 9.1.41.3024
   SiemensSimatic Ipc627d Version-
SiemensSimatic Ipc677d Firmware Version < 9.1.41.3024
   SiemensSimatic Ipc677d Version-
SiemensSimatic Pcs 7 Ipc427e Firmware Version < 21.01.04
   SiemensSimatic Pcs 7 Ipc427e Version-
SiemensSimatic Pcs 7 Ipc547d Firmware Version < 7.1.91.3272
   SiemensSimatic Pcs 7 Ipc547d Version-
SiemensSimatic Pcs 7 Ipc547e Firmware Version < 9.1.41.3024
   SiemensSimatic Pcs 7 Ipc547e Version-
SiemensSimatic Pcs 7 Ipc547g Firmware Version < 11.0.26.3000
   SiemensSimatic Pcs 7 Ipc547g Version-
SiemensSimatic Pcs 7 Ipc627c Firmware Version < 6.2.61.3535
   SiemensSimatic Pcs 7 Ipc627c Version-
SiemensSimatic Pcs 7 Ipc677c Firmware Version < 6.2.61.3535
   SiemensSimatic Pcs 7 Ipc677c Version-
SiemensSimatic Pcs 7 Ipc647c Firmware Version < 6.2.61.3535
   SiemensSimatic Pcs 7 Ipc647c Version-
SiemensSimatic Pcs 7 Ipc647d Firmware Version < 9.1.41.3024
   SiemensSimatic Pcs 7 Ipc647d Version-
SiemensSimatic Pcs 7 Ipc847c Firmware Version < 6.2.61.3535
   SiemensSimatic Pcs 7 Ipc847c Version-
SiemensSimatic Pcs 7 Ipc847d Firmware Version < 9.1.41.3024
   SiemensSimatic Pcs 7 Ipc847d Version-
SiemensSimatic Pcs 7 Ipc547g Firmware Version < 11.0.26.3000
   SiemensSimatic Pcs 7 Ipc547g Version-
SiemensSimatic Ipc427d Firmware Version-
   SiemensSimatic Ipc427d Version-
SiemensSimatic Ipc427e Firmware Version < 21.01.05
   SiemensSimatic Ipc427e Version-
SiemensSimotion P320-4 S Firmware Version < 17.02.06.83.1
   SiemensSimotion P320-4 S Version-
SiemensSinumerik Pcu50.5-p Firmware Version < 6.2.61.3535
   SiemensSinumerik Pcu 50.5-p Version-

28.01.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

Schwachstelle

Intel products contain a vulnerability which can allow attackers to perform privilege escalation.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 94.3% 0.999
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
134c704f-9b21-4f2e-91b3-4a467353bcc0 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-269 Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.