CVE-2017-5689

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
References
Link Resource
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Patch Third Party Advisory
http://www.securityfocus.com/bid/98269 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1038385 Broken Link Third Party Advisory VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf Third Party Advisory
https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf Broken Link
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us Third Party Advisory
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr Patch Vendor Advisory
https://security.netapp.com/advisory/ntap-20170509-0001/ Third Party Advisory
https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf Broken Link Exploit Technical Description Third Party Advisory
https://www.embedi.com/news/mythbusters-cve-2017-5689 Broken Link Third Party Advisory
https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability Technical Description Third Party Advisory
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.html Patch Third Party Advisory
http://www.securityfocus.com/bid/98269 Broken Link Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1038385 Broken Link Third Party Advisory VDB Entry
https://cert-portal.siemens.com/productcert/pdf/ssa-874235.pdf Third Party Advisory
https://downloadmirror.intel.com/26754/eng/INTEL-SA-00075%20Mitigation%20Guide-Rev%201.1.pdf Broken Link
https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbhf03754en_us Third Party Advisory
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00075&languageid=en-fr Patch Vendor Advisory
https://security.netapp.com/advisory/ntap-20170509-0001/ Third Party Advisory
https://www.embedi.com/files/white-papers/Silent-Bob-is-Silent.pdf Broken Link Exploit Technical Description Third Party Advisory
https://www.embedi.com/news/mythbusters-cve-2017-5689 Broken Link Third Party Advisory
https://www.tenable.com/blog/rediscovering-the-intel-amt-vulnerability Technical Description Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2017-5689
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:hpe:proliant_ml10_gen9_server_firmware:5.0:*:*:*:*:*:*:*
cpe:2.3:h:hpe:proliant_ml10_gen9_server:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_itp1000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc847d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847d:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc847c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc847c:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc827d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc827d:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc827c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc827c:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc677d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc677d:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc677c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc677c:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc647d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647d:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc647c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc647c:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc627d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc627d:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc627c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc627c:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc547g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc547g:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc547e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc547e:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc547d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc547d:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
OR cpe:2.3:o:siemens:simatic_ipc477d_firmware:-:*:*:*:-:*:*:*
cpe:2.3:o:siemens:simatic_ipc477d_firmware:-:*:*:*:pro:*:*:*
cpe:2.3:h:siemens:simatic_ipc477d:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m3_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m3:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m4_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m4:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*

Configuration 21 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc627d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc627d:-:*:*:*:*:*:*:*

Configuration 22 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc677d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc677d:-:*:*:*:*:*:*:*

Configuration 23 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc427e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc427e:-:*:*:*:*:*:*:*

Configuration 24 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc547d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc547d:-:*:*:*:*:*:*:*

Configuration 25 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc547e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc547e:-:*:*:*:*:*:*:*

Configuration 26 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc547g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc547g:-:*:*:*:*:*:*:*

Configuration 27 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc627c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc627c:-:*:*:*:*:*:*:*

Configuration 28 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc677c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc677c:-:*:*:*:*:*:*:*

Configuration 29 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc647c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc647c:-:*:*:*:*:*:*:*

Configuration 30 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc647d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc647d:-:*:*:*:*:*:*:*

Configuration 31 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc847c_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc847c:-:*:*:*:*:*:*:*

Configuration 32 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc847d_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc847d:-:*:*:*:*:*:*:*

Configuration 33 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc427e_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc427e:-:*:*:*:*:*:*:*

Configuration 34 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc547g_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc547g:-:*:*:*:*:*:*:*

Configuration 35 (hide)

AND
cpe:2.3:o:siemens:simatic_pcs_7_ipc477d_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_pcs_7_ipc477d:-:*:*:*:*:*:*:*

Configuration 36 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc427d_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc427d:-:*:*:*:*:*:*:*

Configuration 37 (hide)

AND
cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:*

Configuration 38 (hide)

AND
cpe:2.3:o:siemens:simotion_p320-4_s_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:simotion_p320-4_s:-:*:*:*:*:*:*:*

Configuration 39 (hide)

AND
cpe:2.3:o:siemens:sinumerik_pcu50.5-p_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:siemens:sinumerik_pcu_50.5-p:-:*:*:*:*:*:*:*

Configuration 40 (hide)

OR cpe:2.3:o:intel:active_management_technology_firmware:6.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:6.1:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:6.2:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:7.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:7.1:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:8.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:8.1:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:9.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:9.1:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:9.5:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:10.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:11.0:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:11.5:*:*:*:*:*:*:*
cpe:2.3:o:intel:active_management_technology_firmware:11.6:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-05-02 14:59

Updated : 2025-10-22 00:16


NVD link : CVE-2017-5689

Mitre link : CVE-2017-5689

CVE.ORG link : CVE-2017-5689


JSON object : View

Products Affected

siemens

  • simatic_pcs_7_ipc677c_firmware
  • simatic_ipc477d
  • simatic_pcs_7_ipc477d
  • simatic_ipc647c
  • simatic_pcs_7_ipc627c_firmware
  • simatic_field_pg_m3
  • simatic_pcs_7_ipc847c
  • sinumerik_pcu50.5-p_firmware
  • simatic_ipc847d
  • simatic_itp1000
  • simatic_ipc627d_firmware
  • simatic_ipc477e
  • simatic_ipc827d
  • simatic_pcs_7_ipc547d_firmware
  • simatic_ipc647d
  • simatic_ipc547e_firmware
  • simatic_ipc427d_firmware
  • simatic_ipc847c_firmware
  • simatic_field_pg_m5
  • simatic_pcs_7_ipc647d_firmware
  • simatic_ipc647d_firmware
  • simatic_itp1000_firmware
  • simatic_pcs_7_ipc647c
  • simatic_field_pg_m4_firmware
  • simatic_pcs_7_ipc427e_firmware
  • simatic_pcs_7_ipc847d
  • simatic_pcs_7_ipc547e
  • simatic_field_pg_m3_firmware
  • simatic_ipc827c
  • simatic_ipc477d_firmware
  • simatic_ipc627d
  • simatic_ipc547d
  • simatic_ipc627c_firmware
  • simatic_pcs_7_ipc847d_firmware
  • simatic_ipc427e_firmware
  • simatic_ipc427e
  • simatic_pcs_7_ipc547g_firmware
  • simatic_pcs_7_ipc647d
  • simatic_ipc427d
  • simatic_ipc677d
  • simatic_pcs_7_ipc547g
  • simatic_ipc827d_firmware
  • simatic_ipc547d_firmware
  • simatic_ipc547e
  • simotion_p320-4_s
  • simatic_pcs_7_ipc677c
  • simatic_pcs_7_ipc547d
  • simatic_ipc677d_firmware
  • simatic_ipc847c
  • simatic_ipc477e_firmware
  • simatic_ipc647c_firmware
  • simotion_p320-4_s_firmware
  • simatic_ipc547g
  • simatic_ipc847d_firmware
  • simatic_pcs_7_ipc547e_firmware
  • simatic_ipc627c
  • simatic_pcs_7_ipc647c_firmware
  • simatic_ipc547g_firmware
  • simatic_ipc827c_firmware
  • simatic_pcs_7_ipc627c
  • simatic_pcs_7_ipc477d_firmware
  • simatic_pcs_7_ipc847c_firmware
  • sinumerik_pcu_50.5-p
  • simatic_ipc677c
  • simatic_pcs_7_ipc427e
  • simatic_ipc677c_firmware
  • simatic_field_pg_m4
  • simatic_field_pg_m5_firmware

hpe

  • proliant_ml10_gen9_server_firmware
  • proliant_ml10_gen9_server

intel

  • active_management_technology_firmware
CWE
NVD-CWE-noinfo CWE-269

Improper Privilege Management