6.5
CVE-2017-5697
- EPSS 0.21%
- Published 14.06.2017 12:29:00
- Last modified 20.04.2025 01:37:25
- Source secure@intel.com
- Teams watchlist Login
- Open Login
Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.
Data is provided by the National Vulnerability Database (NVD)
Intel ≫ Active Management Technology Firmware Version >= 9.1 < 9.1.40.1000
Intel ≫ Active Management Technology Firmware Version >= 9.5 < 9.5.60.1952
Intel ≫ Active Management Technology Firmware Version >= 10.0 < 10.0.50.1004
Intel ≫ Active Management Technology Firmware Version >= 11.0 < 11.0.0.1205
Intel ≫ Active Management Technology Firmware Version >= 11.6 < 11.6.25.1129
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.404 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain, which can lead to user confusion about which interface the user is interacting with.