CRITICAL · 9.8

CVE-2017-5689

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged ...

Vulnerability Description

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
HpeProliant Ml10 Gen9 Server Firmware5.0
HpeProliant Ml10 Gen9 Server-
SiemensSimatic Itp1000 Firmware< 9.1.41.3024
SiemensSimatic Itp1000-
SiemensSimatic Ipc847D Firmware< 9.1.41.3024
SiemensSimatic Ipc847D-
SiemensSimatic Ipc847C Firmware< 6.2.61.3535
SiemensSimatic Ipc847C-
SiemensSimatic Ipc827D Firmware< 9.1.41.3024
SiemensSimatic Ipc827D-
SiemensSimatic Ipc827C Firmware< 6.2.61.3535
SiemensSimatic Ipc827C-
SiemensSimatic Ipc677D Firmware< 9.1.41.3024
SiemensSimatic Ipc677D-
SiemensSimatic Ipc677C Firmware< 6.2.61.3535
SiemensSimatic Ipc677C-
SiemensSimatic Ipc647D Firmware< 9.1.41.3024
SiemensSimatic Ipc647D-
SiemensSimatic Ipc647C Firmware< 6.2.61.3535
SiemensSimatic Ipc647C-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2017-5689?

CVE-2017-5689 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged ...

How severe is CVE-2017-5689?

CVE-2017-5689 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2017-5689?

Check the references section above for vendor advisories and patch information. Affected products include: Hpe Proliant Ml10 Gen9 Server Firmware, Hpe Proliant Ml10 Gen9 Server, Siemens Simatic Itp1000 Firmware, Siemens Simatic Itp1000, Siemens Simatic Ipc847D Firmware.