Junglewise Threat Intelligence

CVE-2017-5689: Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability

CVE-2017-5689 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-28

Technologies: Intel Active Management Technology (AMT), Intel Standard Manageability. Vendors: Siemens, Hpe, Intel.

Executive brief

A privilege escalation vulnerability in Intel manageability SKUs allows an unprivileged network attacker to gain system privileges on provisioned systems. Additionally, an unprivileged local attacker can provision manageability features to gain network or local system privileges.

Affected products

  • Intel Active Management Technology (AMT)
  • Intel Standard Manageability (ISM)
  • Intel Small Business Technology (SBT)
  • HPE ProLiant ML10 Gen9 Server Firmware 5.0
  • Siemens SIMATIC Field PG M3 Firmware up to (excluding) 6.2.61.3535
  • Siemens SIMATIC Field PG M4 Firmware up to (excluding) 18.01.06
  • Siemens SIMATIC Field PG M5 Firmware up to (excluding) 22.01.03
  • Siemens SIMATIC IPC427E Firmware up to (excluding) 21.01.05
  • Siemens SIMATIC IPC477E Firmware up to (excluding) 21.01.05
  • Siemens SIMATIC IPC547D Firmware up to (excluding) 7.1.91.3272
  • Siemens SIMATIC IPC547E Firmware up to (excluding) 9.1.41.3024
  • Siemens SIMATIC IPC547G Firmware up to (excluding) 11.0.26.3000

Timeline

  • 2017-05-01: advisory: Intel Security Advisory INTEL-SA-00075 published.
  • 2022-01-28: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
  • 2022-01-28: disclosed: NVD publication date.

Related threats