CVE-2017-5689 is a critical vulnerability affecting Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT) in products from vendors like HPE and Siemens. An unprivileged network attacker can gain system privileges, or a local attacker can provision manageability features to achieve the same. With a CVSS score of 9.8 (Critical), this flaw allows for complete compromise (confidentiality, integrity, availability) with low attack complexity and no user interaction. This vulnerability is actively exploited, with Metasploit modules, Nuclei templates, and ExploitDB entries publicly available, and has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.0CPE matchmatch criteria | cpe:2.3:o:hpe:proliant_ml10_gen9_server_firmware:5.0:*:*:*:*:*:*:* | ||
< 9.1.41.3024CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:* | ||
< 9.1.41.3024CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_ipc847d_firmware:*:*:*:*:*:*:*:* | ||
< 6.2.61.3535CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_ipc847c_firmware:*:*:*:*:*:*:*:* | ||
< 9.1.41.3024CPE matchmatch criteria | cpe:2.3:o:siemens:simatic_ipc827d_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.