Vulnerability threat dossier

CVE-2017-5689

hpeproliant ml10 gen9 server

An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).

VTP deterministic threat61.9of 100 · CVSS excluded

VTP analyst assessment

Intel management flaw is known exploited

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityCRITICAL
AI confidence82%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists this Intel AMT, SBT, and ISM privilege-escalation flaw as exploited globally. It can allow an unprivileged network attacker to gain system privileges on provisioned manageability systems.

Why it matters

  • Affected provisioned management features can expose high-impact system access.
  • KEV status confirms known global exploitation, not VTP observation.

Evidence

0 record references and 2 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

No exploit artifact or attack details are supplied.

The supplied evidence does not identify affected systems.

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

Next watchpoint

Review in your environment: if you use Intel AMT, SBT, or ISM, check whether manageability features are provisioned.

AI baseline history (1)
  1. BASELINE ASSESSED
    Intel management flaw is known exploitedgpt-5.6-terra · low
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS0.92100th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 0.92; this is predictive context, not exploitation evidence.

  4. 04

    First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

1publications detected
1underlying evidence chains

0 primary sources · 0 dependent secondary reports · 0 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:OPENVAS_NASL:5999664b9a4b3602d7ad4f674ca76f315d15fbd1ACTIVE
04

Event history

Threat timeline

  1. 02:3623 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 00:0028 Jan
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Exploit tooling coverage changed for 69 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 69 CVEs in this pinned revision. 69 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2016-0792CVE-2016-0870CVE-2016-10107CVE-2016-10108CVE-2016-10140CVE-2016-10401CVE-2016-2107CVE-2016-5649CVE-2016-8346CVE-2016-8722CVE-2016-8724CVE-2016-8725CVE-2016-9361CVE-2017-1000060CVE-2017-10931CVE-2017-14247CVE-2017-14252CVE-2017-14401CVE-2017-14402CVE-2017-14403CVE-2017-14404CVE-2017-14405CVE-2017-14942CVE-2017-17562CVE-2017-18365CVE-2017-20212CVE-2017-20213CVE-2017-20214CVE-2017-20215CVE-2017-20216CVE-2017-20221CVE-2017-20222CVE-2017-20223CVE-2017-20224CVE-2017-3143CVE-2017-3549CVE-2017-3599CVE-2017-5135CVE-2017-5367CVE-2017-5368CVE-2017-5521CVE-2017-5595CVE-2017-5689CVE-2017-5879CVE-2017-5982CVE-2017-6099CVE-2017-7315CVE-2017-7316CVE-2017-7317CVE-2017-7615CVE-2017-8221CVE-2017-8222CVE-2017-8223CVE-2017-8224CVE-2017-8225CVE-2017-8835CVE-2017-8836CVE-2017-8837CVE-2017-8838CVE-2017-8839CVE-2017-8840CVE-2017-8841CVE-2017-8917CVE-2017-9964CVE-2017-9965CVE-2017-9966CVE-2018-17153CVE-2025-34043CVE-2025-34099
Separate evidence group
06

Technical vulnerability data

Context, not threat proof

VTP threat score61.9vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction18.44 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency6 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-269
CPE records
86
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party sensor telemetry is active; no disclosure-eligible deterministic observation is currently public for this CVE. This does not mean no activity was observed.