CVE-2017-5689

CRITICAL KEV NUCLEI

Intel AMT Digest Authentication Bypass Scanner

Title source: metasploit

Description

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

Exploits (9)

exploitdb WORKING POC
by nixawk · pythonremotemultiple
https://www.exploit-db.com/exploits/43385
github WORKING POC 3,480 stars
by qazbnm456 · poc
https://github.com/qazbnm456/awesome-cve-poc/tree/master/CVE-2017-5689.md
nomisec WORKING POC 57 stars
by embedi · client-side
https://github.com/embedi/amt_auth_bypass_poc
nomisec SCANNER 39 stars
by CerberusSecurity · poc
https://github.com/CerberusSecurity/CVE-2017-5689
github WORKING POC 14 stars
by xbl3 · poc
https://github.com/xbl3/awesome-cve-poc_qazbnm456/tree/master/CVE-2017-5689.md
nomisec WORKING POC 3 stars
by Bijaye · remote
https://github.com/Bijaye/intel_amt_bypass
nomisec WORKING POC 1 stars
by MlSebrell · poc
https://github.com/MlSebrell/amthoneypot
nomisec WORKING POC
by TheWay-hue · remote
https://github.com/TheWay-hue/CVE-2017-5689-Checker
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/scanner/http/intel_amt_digest_bypass.rb

Nuclei Templates (1)

Intel Active Management - Authentication Bypass
CRITICALVERIFIEDby pdteam
Shodan: title:"Active Management Technology" || http.title:"active management technology"
FOFA: title="active management technology"

Scores

CVSS v3 9.8
EPSS 0.9419
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-01-28
VulnCheck KEV 2021-08-17
InTheWild.io 2022-01-28
ENISA EUVD EUVD-2017-14766
CWE
CWE-269
Status published
Products (49)
hpe/proliant_ml10_gen9_server_firmware 5.0
intel/active_management_technology_firmware 6.0
intel/active_management_technology_firmware 6.1
intel/active_management_technology_firmware 6.2
intel/active_management_technology_firmware 7.0
intel/active_management_technology_firmware 7.1
intel/active_management_technology_firmware 8.0
intel/active_management_technology_firmware 8.1
intel/active_management_technology_firmware 9.0
intel/active_management_technology_firmware 9.1
... and 39 more
Published May 02, 2017
KEV Added Jan 28, 2022
Tracked Since Feb 18, 2026