cbcvebase.
CVE-2017-5697
published 2017-06-14

CVE-2017-5697: Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and…

PriorityP428medium6.5CVSS 3.1
AVNACLPRNUIRSUCNIHAN
EPSS
0.88%
55.4th percentile
Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.

Affected

11 ranges
VendorProductVersion rangeFixed in
intelactive_management_technology_firmware>= 10.0 < 10.0.50.100410.0.50.1004
intelactive_management_technology_firmware>= 11.0 < 11.0.0.120511.0.0.1205
intelactive_management_technology_firmware>= 11.6 < 11.6.25.112911.6.25.1129
intelactive_management_technology_firmware>= 9.1 < 9.1.40.10009.1.40.1000
intelactive_management_technology_firmware>= 9.5 < 9.5.60.19529.5.60.1952
intel_corporationactive_mangement_technology
oneloginruby-saml>= 0 < 1.11.0-1ubuntu0.11.11.0-1ubuntu0.1
oneloginruby-saml>= 0 < 1.13.0-1ubuntu0.11.13.0-1ubuntu0.1
oneloginruby-saml>= 0 < 1.15.0-1ubuntu0.24.04.11.15.0-1ubuntu0.24.04.1
oneloginruby-saml>= 0 < 1.1.2-1ubuntu1+esm11.1.2-1ubuntu1+esm1
oneloginruby-saml>= 0 < 1.7.2-1ubuntu0.1~esm11.7.2-1ubuntu0.1~esm1

CVSS provenance

nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
osv7.5HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.