CVE-2017-5689

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
References
Link Resource
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Patch Third Party Advisory
http://www.securityfocus.com/bid/98269 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1038385 Third Party Advisory VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf Third Party Advisory
https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf Broken Link
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us Third Party Advisory
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr Patch Vendor Advisory
https://security.netapp.com/advisory/ntap-20170509-0001/ Third Party Advisory
https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf Exploit Technical Description Third Party Advisory
https://www.embedi.com/news/mythbusters-cve-2017-5689 Third Party Advisory
https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability Technical Description Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Patch Third Party Advisory
http://www.securityfocus.com/bid/98269 Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1038385 Third Party Advisory VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf Third Party Advisory
https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf Broken Link
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us Third Party Advisory
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr Patch Vendor Advisory
https://security.netapp.com/advisory/ntap-20170509-0001/ Third Party Advisory
https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf Exploit Technical Description Third Party Advisory
https://www.embedi.com/news/mythbusters-cve-2017-5689 Third Party Advisory
https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability Technical Description Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:intel:active_management_technology_firmware:6.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:6.1:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:6.2:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:7.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:7.1:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:8.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:8.1:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:9.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:9.1:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:9.5:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:10.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:11.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:11.5:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:11.6:*:*:*:*:*:*:*

History

21 Nov 2024, 03:28

Type Values Removed Values Added
References () http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html - Patch, Third Party Advisory () http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html - Patch, Third Party Advisory
References () http://www.securityfocus.com/bid/98269 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/98269 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1038385 - Third Party Advisory, VDB Entry () http://www.securitytracker.com/id/1038385 - Third Party Advisory, VDB Entry
References () https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf - Third Party Advisory () https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf - Third Party Advisory
References () https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf - Broken Link () https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf - Broken Link
References () https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us - Third Party Advisory () https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us - Third Party Advisory
References () https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr - Patch, Vendor Advisory () https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr - Patch, Vendor Advisory
References () https://security.netapp.com/advisory/ntap-20170509-0001/ - Third Party Advisory () https://security.netapp.com/advisory/ntap-20170509-0001/ - Third Party Advisory
References () https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf - Exploit, Technical Description, Third Party Advisory () https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf - Exploit, Technical Description, Third Party Advisory
References () https://www.embedi.com/news/mythbusters-cve-2017-5689 - Third Party Advisory () https://www.embedi.com/news/mythbusters-cve-2017-5689 - Third Party Advisory
References () https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability - Technical Description, Third Party Advisory () https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability - Technical Description, Third Party Advisory

Information

Published : 2017-05-02 14:59

Updated : 2024-11-21 03:28


NVD link : CVE-2017-5689

Mitre link : CVE-2017-5689

CVE.ORG link : CVE-2017-5689


JSON object : View

Products Affected

intel

  • active_management_technology_firmware