CVE-2017-5689
KEV PoC massUnauthenticated Privilege Escalation in Intel AMT, ISM, and SBT Manageability Firmware
CISA: Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
CVE-2017-5689 is a critical (CVSS 9.8) privilege escalation flaw in the manageability features of the Intel Management Engine: Active Management Technology (AMT), Standard Manageability (ISM), and Small Business Technology (SBT), which ship with Intel vPro-class business platforms. An unprivileged remote attacker can exploit it by sending crafted unauthenticated requests to the AMT/ISM network interface (typically TCP ports 16992/16993) on a provisioned system, gaining full system/administrative privileges with no credentials or user interaction. Alternatively, an unprivileged local attacker can provision the manageability features to gain system privileges on AMT, ISM, and SBT. Affected systems include business PCs and workstations with AMT/ISM enabled, plus OEM implementations such as HPE ProLiant ML10 Gen9 servers and a wide range of Siemens SIMATIC industrial PCs, controllers, and panel firmware. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-28, ransomware use unknown), has a public PoC (Embedi's 'Silent Bob is Silent'), and carries a 92.2% EPSS probability of exploitation, so it should be treated as actively exploited.
What to do: Update Intel Management Engine/AMT firmware to the fixed versions released under Intel's May 2017 advisory (SA-00075) via your OEM — apply HPE ProLiant ML10 Gen9 and Siemens SIMATIC firmware updates per vendor instructions, as required by CISA KEV. Until patched, block or restrict ports 16992/16993 at the perimeter, keep AMT confined to trusted management networks, or disable AMT/SBT where not required, and verify provisioned systems with Intel's detection guidance.
| Intel Active Management Technology (AMT) | — |
| Intel Standard Manageability (ISM) | — |
| Intel Small Business Technology (SBT) | — |
| hpe ProLiant ML10 Gen9 Server Firmware | — |
| siemens SIMATIC ITP1000 Firmware | — |
| siemens SIMATIC IPC847D Firmware | — |
| siemens SIMATIC IPC847C Firmware | — |
| siemens SIMATIC IPC827D Firmware | — |
| siemens SIMATIC IPC827C Firmware | — |
| siemens SIMATIC IPC677D Firmware | — |
| siemens SIMATIC IPC677C Firmware | — |
| siemens SIMATIC IPC647D Firmware | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
- Affected
- Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- hpesiemensintel
- Products
- proliant ml10 gen9 server firmware, simatic itp1000 firmware, simatic ipc847d firmware, simatic ipc847c firmware, simatic ipc827d firmware, simatic ipc827c firmware, simatic ipc677d firmware, simatic ipc677c firmware, simatic ipc647d firmware, simatic ipc647c firmware, simatic ipc627d firmware, simatic ipc627c firmware
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H