Manageability Engine Firmware
Vendor:
First CVE: Sep 5, 2017 · Active for 8 years
8
Total CVEs
More Total CVEs than 85% of tracked products
4.0
Avg CVEs / Year
Higher CVE frequency than 83% of tracked products
6.6
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Manageability Engine Firmware over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 5, 2017
8 years ago
Most Recent CVE
Sep 12, 2018
2,872 days ago
CVE Severity & Scoring
Manageability Engine Firmware8 CVEs
50%
50%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local5 (62.5%)
Network3 (37.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High1 (12.5%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low3 (37.5%)
High3 (37.5%)
None2 (25.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-5712HIGH Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access t | Nov 21, 2017 | 7.2 | 27 | NO | NO |
CVE-2017-5708HIGH Multiple privilege escalations in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow unauthorized process to access privileged content via unspecif | Nov 21, 2017 | 7.8 | 26 | NO | NO |
CVE-2017-5705HIGH Multiple buffer overflows in kernel in Intel Manageability Engine Firmware 11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code. | Nov 21, 2017 | 7.8 | 26 | NO | NO |
CVE-2017-5711HIGH Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access | Nov 21, 2017 | 7.8 | 25 | NO | NO |
CVE-2018-3657MEDIUM Multiple buffer overflows in Intel AMT in Intel CSME firmware versions before version 12.0.5 may allow a privileged user to potentially execute arbitrary code with Intel AMT execut | Sep 12, 2018 | 6.7 | 23 | NO | NO |
CVE-2018-3616MEDIUM Bleichenbacher-style side channel vulnerability in TLS implementation in Intel Active Management Technology before 12.0.5 may allow an unauthenticated user to potentially obtain th | Sep 12, 2018 | 5.9 | 22 | NO | NO |
CVE-2018-3658MEDIUM Multiple memory leaks in Intel AMT in Intel CSME firmware versions before 12.0.5 may allow an unauthenticated user with Intel AMT provisioned to potentially cause a partial denial | Sep 12, 2018 | 5.3 | 21 | NO | NO |
CVE-2017-5698MEDIUM Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent | Sep 5, 2017 | 4.4 | 15 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Manageability Engine Firmware
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 11.7 | 4 | 7.7 | 1.6% | 0 | 0 |
| 11.6 | 4 | 7.7 | 1.6% | 0 | 0 |
| 11.5 | 4 | 7.7 | 1.6% | 0 | 0 |
| 11.20 | 4 | 7.7 | 1.6% | 0 | 0 |
| 11.10 | 4 | 7.7 | 1.6% | 0 | 0 |
| 11.0.26.3000 | 1 | 4.4 | 0.3% | 0 | 0 |
| 11.0.25.3001 | 1 | 4.4 | 0.3% | 0 | 0 |
| 11.0 | 4 | 7.7 | 1.6% | 0 | 0 |