CVE-2017-5689

CRITICALCVSS 9.8/10Actively ExploitedEPSS 92.19%

Last modified

CVE-2017-5689 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).. CISA has confirmed active exploitation in the wild. EPSS estimates a 92.19% chance of exploitation in the next 30 days.

Description

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
92.19%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
HpeProliant Ml10 Gen9 Server Firmware5.0
SiemensSimatic Itp1000 Firmware< 9.1.41.3024
SiemensSimatic Ipc847d Firmware< 9.1.41.3024
SiemensSimatic Ipc847c Firmware< 6.2.61.3535
SiemensSimatic Ipc827d Firmware< 9.1.41.3024
SiemensSimatic Ipc827c Firmware< 6.2.61.3535
SiemensSimatic Ipc677d Firmware< 9.1.41.3024
SiemensSimatic Ipc677c Firmware< 6.2.61.3535
SiemensSimatic Ipc647d Firmware< 9.1.41.3024
SiemensSimatic Ipc647c Firmware< 6.2.61.3535
SiemensSimatic Ipc627d Firmware< 9.1.41.3024
SiemensSimatic Ipc627c Firmware< 6.2.61.3535
SiemensSimatic Ipc547g Firmware< 11.0.26.3000
SiemensSimatic Ipc547e Firmware< 9.1.41.3024
SiemensSimatic Ipc547d Firmware< 7.1.91.3272
SiemensSimatic Ipc477e Firmware< 21.01.05
SiemensSimatic Ipc477d FirmwareAll versions
SiemensSimatic Field Pg M3 Firmware< 6.2.61.3535
SiemensSimatic Field Pg M4 Firmware< 18.01.06
SiemensSimatic Field Pg M5 Firmware< 22.01.03
SiemensSimatic Pcs 7 Ipc427e Firmware< 21.01.04
SiemensSimatic Pcs 7 Ipc547d Firmware< 7.1.91.3272
SiemensSimatic Pcs 7 Ipc547e Firmware< 9.1.41.3024
SiemensSimatic Pcs 7 Ipc547g Firmware< 11.0.26.3000
SiemensSimatic Pcs 7 Ipc627c Firmware< 6.2.61.3535
SiemensSimatic Pcs 7 Ipc677c Firmware< 6.2.61.3535
SiemensSimatic Pcs 7 Ipc647c Firmware< 6.2.61.3535
SiemensSimatic Pcs 7 Ipc647d Firmware< 9.1.41.3024
SiemensSimatic Pcs 7 Ipc847c Firmware< 6.2.61.3535
SiemensSimatic Pcs 7 Ipc847d Firmware< 9.1.41.3024
SiemensSimatic Pcs 7 Ipc427e FirmwareAll versions
SiemensSimatic Pcs 7 Ipc477d FirmwareAll versions
SiemensSimatic Ipc427d FirmwareAll versions
SiemensSimatic Ipc427e Firmware< 21.01.05
SiemensSimotion P320-4 S Firmware< 17.02.06.83.1
SiemensSinumerik Pcu50.5-P Firmware< 6.2.61.3535
IntelActive Management Technology Firmware6.0
IntelActive Management Technology Firmware6.1
IntelActive Management Technology Firmware6.2
IntelActive Management Technology Firmware7.0
IntelActive Management Technology Firmware7.1
IntelActive Management Technology Firmware8.0
IntelActive Management Technology Firmware8.1
IntelActive Management Technology Firmware9.0
IntelActive Management Technology Firmware9.1
IntelActive Management Technology Firmware9.5
IntelActive Management Technology Firmware10.0
IntelActive Management Technology Firmware11.0
IntelActive Management Technology Firmware11.5
IntelActive Management Technology Firmware11.6

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2017-5689?
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
How severe is CVE-2017-5689?
CVE-2017-5689 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 92.19% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2017-5689?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-5689?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST