PT-2017-16677 · Intel · Intel Amt
CVE-2017-5697
·
Publicado
2017-06-14
·
Atualizado
2024-01-26
CVSS v3.1
6.5
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Intel AMT firmware versions prior to 9.1.40.1000
Intel AMT firmware versions prior to 9.5.60.1952
Intel AMT firmware versions prior to 10.0.50.1004
Intel AMT firmware versions prior to 11.0.0.1205
Intel AMT firmware versions prior to 11.6.25.1129
Description
The issue is related to insufficient clickjacking protection in the Web User Interface of Intel AMT firmware. This potentially allows a remote attacker to hijack users' web clicks via an attacker's crafted web page.
Recommendations
For versions prior to 9.1.40.1000, update to version 9.1.40.1000 or later.
For versions prior to 9.5.60.1952, update to version 9.5.60.1952 or later.
For versions prior to 10.0.50.1004, update to version 10.0.50.1004 or later.
For versions prior to 11.0.0.1205, update to version 11.0.0.1205 or later.
For versions prior to 11.6.25.1129, update to version 11.6.25.1129 or later.
Correção
Clickjacking
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Intel Amt