Vulnerabilities > Intel > Active Management Technology Firmware

DATE CVE VULNERABILITY TITLE RISK
2017-11-21 CVE-2017-5711 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
local
low complexity
intel asus siemens CWE-119
7.8
2017-09-05 CVE-2017-5698 Unspecified vulnerability in Intel products
Intel Active Management Technology, Intel Standard Manageability, and Intel Small Business Technology firmware versions 11.0.25.3001 and 11.0.26.3000 anti-rollback will not prevent upgrading to firmware version 11.6.x.1xxx which is vulnerable to CVE-2017-5689 and can be performed by a local user with administrative privileges.
local
low complexity
intel
4.4
2017-06-14 CVE-2017-5697 Improper Restriction of Rendered UI Layers or Frames vulnerability in Intel Active Management Technology Firmware
Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.
network
low complexity
intel CWE-1021
6.5
2017-05-02 CVE-2017-5689 Privilege Escalation vulnerability in Multiple Intel Products
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM).
network
low complexity
intel
critical
10.0