CVE-2017-5697

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/06/2017
Last modified:
20/04/2025

Description

Insufficient clickjacking protection in the Web User Interface of Intel AMT firmware versions before 9.1.40.1000, 9.5.60.1952, 10.0.50.1004, 11.0.0.1205, and 11.6.25.1129 potentially allowing a remote attacker to hijack users web clicks via attacker's crafted web page.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 9.1 (including) 9.1.40.1000 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 9.5 (including) 9.5.60.1952 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 10.0 (including) 10.0.50.1004 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 11.0 (including) 11.0.0.1205 (excluding)
cpe:2.3:o:intel:active_management_technology_firmware:*:*:*:*:*:*:*:* 11.6 (including) 11.6.25.1129 (excluding)