cbcvebase.
CVE-2017-5689
published 2017-05-02

CVE-2017-5689: An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel…

PriorityP194critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2022-07-28
Exploited in the wild
EPSS
92.19%
99.8th percentile
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

Affected

52 ranges· showing 25
VendorProductVersion rangeFixed in
hpeproliant_ml10_gen9_server_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelactive_management_technology_firmware
intelmanageability_engine_firmware
intelmanageability_engine_firmware
intelsmall_business_technology_firmware
intelsmall_business_technology_firmware
siemenssimatic_field_pg_m3_firmware< 6.2.61.35356.2.61.3535
siemenssimatic_field_pg_m4_firmware< 18.01.0618.01.06
siemenssimatic_field_pg_m5_firmware< 22.01.0322.01.03
siemenssimatic_ipc427e_firmware< 21.01.0521.01.05

Detection & IOCsextracted from sources · hover to see the quote

port16992
port16993
port623
port16994
port16995
port664
  • Nessus plugin #97999 actively confirms CVE-2017-5689 by performing the authentication bypass against a provisioned AMT service.
  • Nessus plugin #97998 detects vulnerable AMT versions via the service banner on port 16992; note it may produce false negatives due to banner granularity.
  • Nessus plugin #97997 (credentialed) detects affected Intel AMT systems and provides remediation guidance.
  • PVS/Nessus Network Monitor plugin #6955 detects hosts with AMT running passively.
  • Nessus plugin #105778 detects Intel AMT remote access enabled by inspecting the banner of the service on port 16992.
  • Nessus plugin #102992 identifies systems potentially at risk for AMT-related vulnerabilities without requiring a new scan.
  • Network scanners (SYN and TCP) must be used in addition to local scanner, as the Intel AMT ports are not visible to the OS and cannot be enumerated locally.
  • Scan policy must explicitly probe ports 16992, 16993, and 623 beyond default ports to detect AMT exposure.
  • Block or disable ports 16992–16995 at the network perimeter to mitigate exploitation of CVE-2017-5689.
  • ·The Intel AMT ports (16992, 16993, etc.) are not visible to the host OS; local port enumeration will miss them. Network-based SYN/TCP scanners must be used.
  • ·For SecurityCenter, the keyword 'default' must be removed from the scan template when specifying AMT ports, otherwise data will not be collected properly.
  • ·Banner-based detection (plugin #97998) may produce false negatives because banner versions are not always granular enough to distinguish all vulnerable versions.
  • ·The vulnerability only affects systems where AMT has been explicitly enabled; it does not impact all Intel chipsets and has greater impact on servers than consumer PCs.

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vulncheck9.8CRITICAL
cisa9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.