Actively exploited in the wild. This CVE is on the CISA Known Exploited Vulnerabilities list — treat remediation as urgent. Federal remediation due by 28 Jul 2022.
Proliant Ml10 Gen9 Server FirmwareOperating system · Hpe

CVE-2017-5689

CRITICAL · 9.8 CVSS v3.1 Published 2017-05-02
Fix available
A fix is available. Upgrade to 6.2.61.3535 / 9.1.41.3024 or later.
See remediation →
100/100
Remediation priority · Urgent
In the wild High EPSS Public exploit Remotely reachable No privileges Zero-click Patch available

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

Intel AMT/ISM/SBT contain an authentication bypass vulnerability where the digest authentication sequence can be manipulated to bypass verification, allowing an unprivileged attacker to gain system privileges. The network attack vector allows remote compromise of provisioned AMT systems, while local attackers can provision manageability features to escalate privileges.

MitigationApply Intel's firmware updates for affected manageability firmware, disable AMT/ISM/SBT if not required, and ensure default admin passwords are changed with strong credentials.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
Proliant Ml10 Gen9 Server FirmwareOperating system
Affected:= 5.0
Simatic Itp1000 FirmwareOperating system
Affected:< 9.1.41.3024
Simatic Ipc847d FirmwareOperating system
Affected:< 9.1.41.3024
Simatic Ipc847c FirmwareOperating system
Affected:< 6.2.61.3535
Simatic Ipc827d FirmwareOperating system
Affected:< 9.1.41.3024
Simatic Ipc827c FirmwareOperating system
Affected:< 6.2.61.3535
Simatic Ipc677d FirmwareOperating system
Affected:< 9.1.41.3024
Simatic Ipc677c FirmwareOperating system
Affected:< 6.2.61.3535

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Confirm Intel AMT or ISM is enabled
    Access the system BIOS/UEFI settings and look for Intel AMT (Active Management Technology) or Intel ISM (Standard Manageability) settings under the 'Manageability' or 'Security' sections. Alternatively, on a running system, access the AMT web interface typically at https://<management_port> (port 16992 or 16993) if configured.
    Affected if Intel AMT or ISM is enabled and accessible on the network or locally.
  2. Identify the Intel Management Engine firmware version
    If AMT is accessible, log into the AMT web interface and navigate to the firmware version information page, typically under 'General' > ' firmware version'. Alternatively, use the Intel Management Engine Interface (MEI) tool or 'intelmetool' on Linux to query the Management Engine version.
    Affected if The Management Engine firmware version falls within vulnerable versions (prior to the 2017 Intel security update) and matches the affected Intel AMT/ISM SKUs.
  3. Check HPE ProLiant ML10 Gen9 firmware version
    For the HPE ProLiant ML10 Gen9, access the iLO (Integrated Lights-Out) web interface or BIOS and locate the System ROM or iLO firmware version information. Compare against version 5.0.
    Affected if The system is an HPE ProLiant ML10 Gen9 with firmware version exactly equal to 5.0.
  4. Check Siemens Simatic IPC firmware versions
    For Siemens Simatic IPC models (IPC847d, IPC827d, IPC677d), access the device management interface or boot into the firmware update utility to view the current firmware version. Compare against the affected version thresholds.
    Affected if The device is a Simatic IPC847d, IPC827d, or IPC677d with firmware version less than 9.1.41.3024, or a Simatic IPC847c, IPC827c, or IPC677c with firmware version less than 6.2.61.3535.
  5. Verify network accessibility of AMT interface
    Scan the network for open ports 16992 (HTTP) and 16993 (HTTPS) which are default Intel AMT HTTP/HTTPS ports. Use a tool like nmap: nmap -p 16992,16993 <target_ip>.
    Affected if Ports 16992 or 16993 are open and the AMT web interface is reachable from an untrusted network segment.

Your system is affected if Intel AMT or ISM is enabled and the firmware version is below the patched versions, particularly if you are using any of the listed HPE or Siemens product firmware versions.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

dbcve · scoped
Upgrade available Upgrade to 6.2.61.3535 / 9.1.41.3024 or later
Fixed in 6.2.61.35359.1.41.3024
Vendor patch www.oracle.com →
Interim mitigation

Apply Intel's firmware updates for affected manageability firmware, disable AMT/ISM/SBT if not required, and ensure default admin passwords are changed with strong credentials.

Recommended fix High confidence

HP Proliant: latest firmware post-5.0; Simatic ITP1000/IPC827d/IPC677d/IPC847d: firmware >= 9.1.41.3024; Simatic IPC847c/IPC827c/IPC677c: firmware >= 6.2.61.3535; Intel AMT/ISM: security patch released by Intel in 2017

  1. 1. Identify the specific device model and current firmware version from the affected list (Proliant ML10 Gen9, Simatic ITP1000, IPC847d, IPC847c, IPC827d, IPC827c, IPC677d, or IPC677c).
  2. 2. For HP Proliant ML10 Gen9: Download the latest HP firmware update from h20566.www2.hpe.com or HP support portal.
  3. 3. For Siemens Simatic devices: Download the appropriate firmware patch from cert-portal.siemens.com matching your specific model and revision.
  4. 4. For Intel AMT/ISM systems: Obtain the Intel firmware update from downloadmirror.intel.com or Intel support.
  5. 5. Apply the firmware update following vendor-specific instructions (typically requires server/local console access).
  6. 6. After update, verify the firmware version has been patched to a version higher than the vulnerable releases.
  7. 7. As an additional mitigation, consider disabling Intel AMT/ISM/SBT if not required, or implementing network isolation to restrict access to manageability interfaces.
Caveat Firmware updates may require downtime and should be tested in a staging environment before production deployment; some legacy manageability features may behave differently after patching

Generated from the published advisory — verify against the referenced sources before acting.

Fix this in Proliant Ml10 Gen9 Server Firmware Exploited in the wild — priority engagement
  • Consultation6.0 h
  • Implementation12.0 h
  • Testing4.0 h
  • Review / QA3.0 h
25.0 hours of engineering $4,500
Get it fixed fast

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $7,200.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2017-5689 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2017-5689 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data