CVE-2017-5689General(hpe / active_management_technology_firmware)

HIGHCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch hpe active_management_technology_firmware systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

6.5/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2022-07-28. Apply updates per vendor instructions.

Weakness type (CWE)
CWE-269

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_management_technology_firmware
  • proliant_ml10_gen9_server
  • proliant_ml10_gen9_server_firmware
  • simatic_field_pg_m3

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 9 mentions across 6 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 1 signal
  • General: 6 classified signals
  • Peaked 4d ago at 3 mentions (2026-02-11); latest day: 1
  • 9 total mentions across 6 days

Affected systems

Products
active_management_technology_firmwareproliant_ml10_gen9_serverproliant_ml10_gen9_server_firmwaresimatic_field_pg_m3simatic_field_pg_m3_firmwaresimatic_field_pg_m4simatic_field_pg_m4_firmwaresimatic_field_pg_m5simatic_field_pg_m5_firmwaresimatic_ipc427d

16 versions affected across 71 products

Deep dive

Activity timeline9 mentions / 6d
01223Mentions · 2026-02-10: 2Mentions · 2026-02-11: 3Mentions · 2026-03-21: 1Mentions · 2026-05-24: 1Mentions · 2026-06-05: 1Mentions · 2026-09-23: 1PoC Mentioned / Linked · 2026-02-10: 1PoC Mentioned / Linked · 2026-02-11: 1Active Exploitation · 2026-03-21: 1Patch / Workaround · 2026-02-10: 1Patch / Workaround · 2026-02-11: 1Technical Details · 2026-02-11: 102-1002-1103-2105-2406-0509-23
Signal classification3 categories
General
666.7%
PoC
222.2%
Patch
111.1%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-102
General1PoC1
2026-02-113
General1Patch1PoC1
2026-03-211
General1
2026-05-241
General1
2026-06-051
General1
2026-09-231
General1
Full discourse9 posts
  • ؘ@scelerada
    General

    pesquisem sobre as CVEs CVE-2017-5688 e CVE-2017-5689

    Post summary

    The text merely mentions CVE-2017-5688 and CVE-2017-5689 and advises researching them, without providing any details about PoC, exploits, patches, or active exploitation.

    1301787210.3K
    588 followersView on X
  • Jack Graham@Rageagainstfem
    General

    @retaskuu @kunaiposting CVE-2017-5689

    Post summary

    The tweet references CVE-2017-5689 but provides no additional information, details, or context.

    1005554.3K
    41 followersView on X
  • bigproblem@MyMindSpray
    PoC

    @retaskuu @Rageagainstfem @kunaiposting https://www.exploit-db.com/docs/english/48226-manually-exploiting-intel-amt-vulnerability-cve-2017-5689-%5Bpaper%5D.pdf ? https://t.co/eZTUaZfWUL

    Post summary

    A link to an Exploit‑DB paper is shared that documents a manual exploitation of CVE‑2017‑5689, indicating a PoC is available but no additional exploitation details or mitigations are provided.

    10060181
    140 followersView on X
  • Sakureil@sakuureil
    Patch

    @pacific_noble @kunaiposting CVE-2017-5689 requires you first buy a vPro CPU (extra charge) and have ENABLED and PROVISIONED AMT. The bug has been patched for almost a decade. And see that "no peer-reviewed evidence confirms deliberate NSA-mandated backdoors." Intel denies they have ever backdoored products

    Post summary

    The post confirms that CVE-2017-5689 has been patched for years and notes no evidence of active exploitation or backdoor claims.

    20050586
    1.5K followersView on X
  • mersomas@mersomas
    General

    @choehau_ara the intel management system is a mess, so insecure in fact that most exploits could be done remotely (like the CVE-2017-5689), they still haven't made any effort to improve security, and exploits are still doable (Apple's SEP and AMD's PSP are WAYYYY more secure )

    Post summary

    The tweet references CVE-2017-5689 and states that Intel’s management system is insecure, but it provides no proof of concept, exploit code, patch information, evidence of active exploitation, or technical details.

    20021193
    1.0K followersView on X
  • Matías N. Goldberg@matiasgoldberg
    PoC

    More info: https://www.vicarius.io/vsociety/posts/intel-active-management-technology-rce-exploit-analysis-cve-2017-5689 History is cursed to repeat itself. Another fun fact: This exploit worked even if the computer was powered off. You'd have to physically unplug it. Fortunately, this feature was off by default so the damage wasn't widespread.

    Post summary

    The post links to a detailed analysis of CVE‑2017‑5689, noting that the exploit works even when the computer is powered off but is mitigated by the feature being off by default.

    10010369
    5.3K followersView on X
  • Bairrista@EoWFS
    General

    Backdoor do governo dos EUA ficou ativo no Linux por 10 anos até uns chineses descobrirem https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Backdoor:Linux/BVP47.A!MTB Backdoor do XZ CVE-2024-3094 Backdoor do Intel AMT CVE-2017-5689 E isso é o que eu lembro, teve um doidinho num fórum que tinha uma lista gigante

    Post summary

    El texto menciona un backdoor gubernamental activo en Linux durante una década y enumera varios CVEs y nombres de backdoors, sin proporcionar detalles técnicos, PoC, exploit o información de parche.

    0000179
    678 followersView on X
  • galalau.com@largatixaasian_
    General

    @sinanzm @ysszzzy @cherrybibs n eh teoria, é literalmente documentado isso ai kkkkk CVE-2017-5689 CVE-2017-5688

    Post summary

    The post simply cites two CVE identifiers without providing any additional context, technical details, or actionable information.

    0000044
    217 followersView on X
  • Grok@grok
    General

    Intel Management Engine (IME), Intel işlemcilerde bağımsız çalışan bir alt sistemdir. Uzaktan yönetim, güvenlik ve güç kontrolü sağlar. Güç bağlıyken bile aktif kalır, ancak güvenlik açıkları (ör. CVE-2017-5689) nedeniyle tartışmalıdır; devre dışı bırakmak zordur. AMD Platform Security Processor (PSP), AMD CPU'larda gömülü ARM tabanlı güvenlik işlemcisidir. Güvenli önyükleme, şifreleme ve kod doğrulama gibi özellikler sunar. IME'ye benzer şekilde sistem güvenliğini artırır, ancak benzer güvenlik riskleri taşır.

    Post summary

    The passage notes that Intel Management Engine and AMD PSP have security vulnerabilities (e.g., CVE‑2017‑5689) but provides no technical specifics, exploit evidence, or mitigation guidance.

    0000031
    8.1M followersView on X
CPE platform detail86 entries

86 of 86 entries

PartVendorProductVersionTarget SWTarget HW
HWhpeproliant_ml10_gen9_server---
OShpeproliant_ml10_gen9_server_firmware5.0--
OSintelactive_management_technology_firmware10.0--
OSintelactive_management_technology_firmware11.0--
OSintelactive_management_technology_firmware11.5--
OSintelactive_management_technology_firmware11.6--
OSintelactive_management_technology_firmware6.0--
OSintelactive_management_technology_firmware6.1--
OSintelactive_management_technology_firmware6.2--
OSintelactive_management_technology_firmware7.0--
OSintelactive_management_technology_firmware7.1--
OSintelactive_management_technology_firmware8.0--
OSintelactive_management_technology_firmware8.1--
OSintelactive_management_technology_firmware9.0--
OSintelactive_management_technology_firmware9.1--
OSintelactive_management_technology_firmware9.5--
HWsiemenssimatic_field_pg_m3---
OSsiemenssimatic_field_pg_m3_firmware---
HWsiemenssimatic_field_pg_m4---
OSsiemenssimatic_field_pg_m4_firmware---
HWsiemenssimatic_field_pg_m5---
OSsiemenssimatic_field_pg_m5_firmware---
HWsiemenssimatic_ipc427d---
OSsiemenssimatic_ipc427d_firmware---
HWsiemenssimatic_ipc427e---
OSsiemenssimatic_ipc427e_firmware---
HWsiemenssimatic_ipc477d---
OSsiemenssimatic_ipc477d_firmware---
OSsiemenssimatic_ipc477d_firmware---
HWsiemenssimatic_ipc477e---
OSsiemenssimatic_ipc477e_firmware---
HWsiemenssimatic_ipc547d---
OSsiemenssimatic_ipc547d_firmware---
HWsiemenssimatic_ipc547e---
OSsiemenssimatic_ipc547e_firmware---
HWsiemenssimatic_ipc547g---
OSsiemenssimatic_ipc547g_firmware---
HWsiemenssimatic_ipc627c---
OSsiemenssimatic_ipc627c_firmware---
HWsiemenssimatic_ipc627d---
OSsiemenssimatic_ipc627d_firmware---
HWsiemenssimatic_ipc647c---
OSsiemenssimatic_ipc647c_firmware---
HWsiemenssimatic_ipc647d---
OSsiemenssimatic_ipc647d_firmware---
HWsiemenssimatic_ipc677c---
OSsiemenssimatic_ipc677c_firmware---
HWsiemenssimatic_ipc677d---
OSsiemenssimatic_ipc677d_firmware---
HWsiemenssimatic_ipc827c---
OSsiemenssimatic_ipc827c_firmware---
HWsiemenssimatic_ipc827d---
OSsiemenssimatic_ipc827d_firmware---
HWsiemenssimatic_ipc847c---
OSsiemenssimatic_ipc847c_firmware---
HWsiemenssimatic_ipc847d---
OSsiemenssimatic_ipc847d_firmware---
HWsiemenssimatic_itp1000---
OSsiemenssimatic_itp1000_firmware---
HWsiemenssimatic_pcs_7_ipc427e---
OSsiemenssimatic_pcs_7_ipc427e_firmware---
OSsiemenssimatic_pcs_7_ipc427e_firmware---
HWsiemenssimatic_pcs_7_ipc477d---
OSsiemenssimatic_pcs_7_ipc477d_firmware---
HWsiemenssimatic_pcs_7_ipc547d---
OSsiemenssimatic_pcs_7_ipc547d_firmware---
HWsiemenssimatic_pcs_7_ipc547e---
OSsiemenssimatic_pcs_7_ipc547e_firmware---
HWsiemenssimatic_pcs_7_ipc547g---
OSsiemenssimatic_pcs_7_ipc547g_firmware---
HWsiemenssimatic_pcs_7_ipc627c---
OSsiemenssimatic_pcs_7_ipc627c_firmware---
HWsiemenssimatic_pcs_7_ipc647c---
OSsiemenssimatic_pcs_7_ipc647c_firmware---
HWsiemenssimatic_pcs_7_ipc647d---
OSsiemenssimatic_pcs_7_ipc647d_firmware---
HWsiemenssimatic_pcs_7_ipc677c---
OSsiemenssimatic_pcs_7_ipc677c_firmware---
HWsiemenssimatic_pcs_7_ipc847c---
OSsiemenssimatic_pcs_7_ipc847c_firmware---
HWsiemenssimatic_pcs_7_ipc847d---
OSsiemenssimatic_pcs_7_ipc847d_firmware---
HWsiemenssimotion_p320-4_s---
OSsiemenssimotion_p320-4_s_firmware---
OSsiemenssinumerik_pcu50.5-p_firmware---
HWsiemenssinumerik_pcu_50.5-p---

Explore more