CVE-2017-5711

Published: Nov 21, 2017 Last Modified: Apr 20, 2025 EU-VD ID: EUVD-2017-14788 Aliases: GSD-2017-5711
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,8
Attack Vector: local
Attack Complexity: low
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
HIGH 7,2
Access Vector: local
Access Complexity: low
Authentication: none
Confidentiality: complete
Integrity: complete
Availability: complete

Description

AI Translation Available

Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0015
Percentile
0,4th
Updated

EPSS Score Trend (Last 90 Days)

119

Improper Restriction of Operations within the Bounds of a Memory Buffer

Stable
Common Consequences
Security Scopes Affected:
Integrity Confidentiality Availability
Potential Impacts:
Execute Unauthorized Code Or Commands Modify Memory Read Memory Dos: Crash, Exit, Or Restart Dos: Resource Consumption (Cpu) Dos: Resource Consumption (Memory)
Applicable Platforms
Languages: Assembly, C, C++, Memory-Unsafe
View CWE Details
Operating System

Z170M-Plus\/Br Firmware by Asus

cpe:2.3:o:asus:z170m-plus\/br_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc627D Firmware by Siemens

Version Range Affected
To 9.1.41.3024 (exclusive)
cpe:2.3:o:siemens:simatic_ipc627d_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H170M-Plus\/Br Firmware by Asus

cpe:2.3:o:asus:h170m-plus\/br_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime J3355I-C Firmware by Asus

cpe:2.3:o:asus:prime_j3355i-c_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Viii Impact Firmware by Asus

cpe:2.3:o:asus:rog_maximus_viii_impact_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tuf Z370-Plus Gaming Firmware by Asus

cpe:2.3:o:asus:tuf_z370-plus_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Ix Formula Firmware by Asus

cpe:2.3:o:asus:rog_maximus_ix_formula_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-C\/Br Firmware by Asus

cpe:2.3:o:asus:b150m-c\/br_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170I Pro Gaming Firmware by Asus

cpe:2.3:o:asus:z170i_pro_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-K Firmware by Asus

cpe:2.3:o:asus:h110m-k_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Field Pg M5 Firmware by Siemens

Version Range Affected
To 22.01.04 (exclusive)
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150-A Firmware by Asus

cpe:2.3:o:asus:b150-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-P D3 Firmware by Asus

cpe:2.3:o:asus:z170-p_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Viii Hero Alpha Firmware by Asus

cpe:2.3:o:asus:rog_maximus_viii_hero_alpha_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-A D3 Firmware by Asus

cpe:2.3:o:asus:h110m-a_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

Version Range Affected
From 9.0.0.0 (inclusive)
To 9.1.41.3024 (inclusive)
cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-Cs Firmware by Asus

cpe:2.3:o:asus:h110m-cs_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z370-G Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z370-g_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110I-Plus Firmware by Asus

cpe:2.3:o:asus:h110i-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Viii Formula Firmware by Asus

cpe:2.3:o:asus:rog_maximus_viii_formula_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-F Firmware by Asus

cpe:2.3:o:asus:h110m-f_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime H270-Plus Firmware by Asus

cpe:2.3:o:asus:prime_h270-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix B250F Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_b250f_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110-Plus Firmware by Asus

cpe:2.3:o:asus:h110-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Z270-A Firmware by Asus

cpe:2.3:o:asus:prime_z270-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-K D3 Firmware by Asus

cpe:2.3:o:asus:h110m-k_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q270M-Cm-A Firmware by Asus

cpe:2.3:o:asus:q270m-cm-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

cpe:2.3:o:intel:manageability_engine_firmware:11.6:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150-Pro Firmware by Asus

cpe:2.3:o:asus:b150-pro_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus X Apex Firmware by Asus

cpe:2.3:o:asus:rog_maximus_x_apex_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-E Firmware by Asus

cpe:2.3:o:asus:z170-e_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-K D3 Firmware by Asus

cpe:2.3:o:asus:b150m-k_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q170T Firmware by Asus

cpe:2.3:o:asus:q170t_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-C2\/Tf Firmware by Asus

cpe:2.3:o:asus:h110m-c2\/tf_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H170M-E D3 Firmware by Asus

cpe:2.3:o:asus:h170m-e_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc547E Firmware by Siemens

Version Range Affected
To 9.1.41.3024 (exclusive)
cpe:2.3:o:siemens:simatic_ipc547e_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Active Management Technology Firmware by Intel

cpe:2.3:o:intel:active_management_technology_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Pio-B150M Firmware by Asus

cpe:2.3:o:asus:pio-b150m_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-B150M-V5 Firmware by Asus

cpe:2.3:o:asus:ex-b150m-v5_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-C2 Firmware by Asus

cpe:2.3:o:asus:h110m-c2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B250-Mr Firmware by Asus

cpe:2.3:o:asus:b250-mr_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime H270M-Plus Firmware by Asus

cpe:2.3:o:asus:prime_h270m-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-Ar Firmware by Asus

cpe:2.3:o:asus:z170-ar_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

cpe:2.3:o:intel:manageability_engine_firmware:11.7:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simotion P320-4S Firmware by Siemens

Version Range Affected
To 17.02.06.83.1 (exclusive)
cpe:2.3:o:siemens:simotion_p320-4s_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Ix Extreme Firmware by Asus

cpe:2.3:o:asus:rog_maximus_ix_extreme_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc827C Firmware by Siemens

Version Range Affected
To 6.2.61.3535 (exclusive)
cpe:2.3:o:siemens:simatic_ipc827c_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-Plus Firmware by Asus

cpe:2.3:o:asus:h110m-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

cpe:2.3:o:intel:manageability_engine_firmware:11.20:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

cpe:2.3:o:intel:manageability_engine_firmware:11.0:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250-Plus Firmware by Asus

cpe:2.3:o:asus:prime_b250-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110S2 Firmware by Asus

cpe:2.3:o:asus:h110s2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc547D Firmware by Siemens

Version Range Affected
To 7.1.91.3272 (exclusive)
cpe:2.3:o:siemens:simatic_ipc547d_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-B250M-V Firmware by Asus

cpe:2.3:o:asus:ex-b250m-v_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z270F Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z270f_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110T-A Firmware by Asus

cpe:2.3:o:asus:h110t-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z370-H Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z370-h_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250M-D Firmware by Asus

cpe:2.3:o:asus:prime_b250m-d_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc677D Firmware by Siemens

Version Range Affected
To 9.1.41.3024 (exclusive)
cpe:2.3:o:siemens:simatic_ipc677d_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H170M-Plus Firmware by Asus

cpe:2.3:o:asus:h170m-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus X Code Firmware by Asus

cpe:2.3:o:asus:rog_maximus_x_code_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M Pro Gaming Firmware by Asus

cpe:2.3:o:asus:b150m_pro_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

cpe:2.3:o:intel:manageability_engine_firmware:11.5:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Sinumerik Pcu50.5-P Firmware by Siemens

Version Range Affected
To 6.2.61.3535 (exclusive)
cpe:2.3:o:siemens:sinumerik_pcu50.5-p_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170M-E D3 Firmware by Asus

cpe:2.3:o:asus:z170m-e_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q170M2 Firmware by Asus

cpe:2.3:o:asus:q170m2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250M-C Firmware by Asus

cpe:2.3:o:asus:prime_b250m-c_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H170I-Pro Firmware by Asus

cpe:2.3:o:asus:h170i-pro_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B250 Mining Expert Firmware by Asus

cpe:2.3:o:asus:b250_mining_expert_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B250M-C Pro Firmware by Asus

cpe:2.3:o:asus:b250m-c_pro_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-F Plus Firmware by Asus

cpe:2.3:o:asus:b150m-f_plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tuf Z270 Mark 1 Firmware by Asus

cpe:2.3:o:asus:tuf_z270_mark_1_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-Ks Firmware by Asus

cpe:2.3:o:asus:h110m-ks_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Z270-Ar Firmware by Asus

cpe:2.3:o:asus:prime_z270-ar_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-Cs X Firmware by Asus

cpe:2.3:o:asus:h110m-cs_x_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-K X Firmware by Asus

cpe:2.3:o:asus:h110m-k_x_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc477D Firmware by Siemens

cpe:2.3:o:siemens:simatic_ipc477d_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Z270-K Firmware by Asus

cpe:2.3:o:asus:prime_z270-k_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-Plus Firmware by Asus

cpe:2.3:o:asus:b150m-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150 Pro Gaming D3 Firmware by Asus

cpe:2.3:o:asus:b150_pro_gaming_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-K Firmware by Asus

cpe:2.3:o:asus:z170-k_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q170M2\/Cdm\/Si Firmware by Asus

cpe:2.3:o:asus:q170m2\/cdm\/si_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

cpe:2.3:o:intel:manageability_engine_firmware:11.10:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250M-J Firmware by Asus

cpe:2.3:o:asus:prime_b250m-j_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc827D Firmware by Siemens

Version Range Affected
To 9.1.41.3024 (exclusive)
cpe:2.3:o:siemens:simatic_ipc827d_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110T Firmware by Asus

cpe:2.3:o:asus:h110t_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix B250I Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_b250i_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime H110M2\/Fpt Firmware by Asus

cpe:2.3:o:asus:prime_h110m2\/fpt_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q170S1 Firmware by Asus

cpe:2.3:o:asus:q170s1_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc647C Firmware by Siemens

Version Range Affected
To 6.2.61.3535 (exclusive)
cpe:2.3:o:siemens:simatic_ipc647c_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-C\/Ps Firmware by Asus

cpe:2.3:o:asus:h110m-c\/ps_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime H110M-P Firmware by Asus

cpe:2.3:o:asus:prime_h110m-p_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250M-A Firmware by Asus

cpe:2.3:o:asus:prime_b250m-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc477D Pro Firmware by Siemens

cpe:2.3:o:siemens:simatic_ipc477d_pro_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-B150M-V3 Firmware by Asus

cpe:2.3:o:asus:ex-b150m-v3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H170-Plus D3 Firmware by Asus

cpe:2.3:o:asus:h170-plus_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-P\/Dvi Firmware by Asus

cpe:2.3:o:asus:h110m-p\/dvi_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix H270F Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_h270f_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Z270M-Plus\/Br Firmware by Asus

cpe:2.3:o:asus:prime_z270m-plus\/br_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150 Pro Gaming\/Aura Firmware by Asus

cpe:2.3:o:asus:b150_pro_gaming\/aura_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z270H Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z270h_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q170T V2 Firmware by Asus

cpe:2.3:o:asus:q170t_v2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Sabertooth Z170 S Firmware by Asus

cpe:2.3:o:asus:sabertooth_z170_s_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-A\/M.2 Firmware by Asus

cpe:2.3:o:asus:h110m-a\/m.2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-C\/Br Firmware by Asus

cpe:2.3:o:asus:h110m-c\/br_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-Cs\/Br Firmware by Asus

cpe:2.3:o:asus:h110m-cs\/br_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-V Plus Firmware by Asus

cpe:2.3:o:asus:b150m-v_plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Trooper B150 D3 Firmware by Asus

cpe:2.3:o:asus:trooper_b150_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Ix Code Firmware by Asus

cpe:2.3:o:asus:rog_maximus_ix_code_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime H110M2 Firmware by Asus

cpe:2.3:o:asus:prime_h110m2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime H270-Pro Firmware by Asus

cpe:2.3:o:asus:prime_h270-pro_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Pio-B250I Firmware by Asus

cpe:2.3:o:asus:pio-b250i_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus X Hero Firmware by Asus

cpe:2.3:o:asus:rog_maximus_x_hero_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-E Firmware by Asus

cpe:2.3:o:asus:h110m-e_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix B250H Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_b250h_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc477E Firmware by Siemens

Version Range Affected
To 21.01.07 (exclusive)
cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-C Firmware by Asus

cpe:2.3:o:asus:h110m-c_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-D\/Exper\/Si Firmware by Asus

cpe:2.3:o:asus:h110m-d\/exper\/si_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-E\/M.2 Firmware by Asus

cpe:2.3:o:asus:h110m-e\/m.2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H170-Pro\/Usb 3.1 Firmware by Asus

cpe:2.3:o:asus:h170-pro\/usb_3.1_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-Ks R1 Firmware by Asus

cpe:2.3:o:asus:h110m-ks_r1_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q170M-C Firmware by Asus

cpe:2.3:o:asus:q170m-c_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q170M-Cm-B Firmware by Asus

cpe:2.3:o:asus:q170m-cm-b_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250-Pro Firmware by Asus

cpe:2.3:o:asus:prime_b250-pro_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250-A Firmware by Asus

cpe:2.3:o:asus:prime_b250-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170 Pro Gaming Firmware by Asus

cpe:2.3:o:asus:z170_pro_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-A Firmware by Asus

cpe:2.3:o:asus:b150m-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-C\/Hdmi Firmware by Asus

cpe:2.3:o:asus:h110m-c\/hdmi_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tuf Z370-Pro Gaming Firmware by Asus

cpe:2.3:o:asus:tuf_z370-pro_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Field Pg M3 Firmware by Siemens

Version Range Affected
To 6.2.61.3535 (exclusive)
cpe:2.3:o:siemens:simatic_field_pg_m3_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z270G Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z270g_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-B250-V7 Firmware by Asus

cpe:2.3:o:asus:ex-b250-v7_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150I Pro Gaming\/Wifi\/Aura Firmware by Asus

cpe:2.3:o:asus:b150i_pro_gaming\/wifi\/aura_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Field Pg M4 Firmware by Siemens

Version Range Affected
To 18.01.06 (exclusive)
cpe:2.3:o:siemens:simatic_field_pg_m4_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Viii Extreme Firmware by Asus

cpe:2.3:o:asus:rog_maximus_viii_extreme_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc427D Firmware by Siemens

cpe:2.3:o:siemens:simatic_ipc427d_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc647D Firmware by Siemens

Version Range Affected
To 9.1.41.3024 (exclusive)
cpe:2.3:o:siemens:simatic_ipc647d_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-D Firmware by Asus

cpe:2.3:o:asus:b150m-d_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150-Pro D3 Firmware by Asus

cpe:2.3:o:asus:b150-pro_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Viii Hero Firmware by Asus

cpe:2.3:o:asus:rog_maximus_viii_hero_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250M-Plus\/Br Firmware by Asus

cpe:2.3:o:asus:prime_b250m-plus\/br_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Q270M-C Firmware by Asus

cpe:2.3:o:asus:prime_q270m-c_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-Premium Firmware by Asus

cpe:2.3:o:asus:z170-premium_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170M-Plus Firmware by Asus

cpe:2.3:o:asus:z170m-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Z270M-Plus Firmware by Asus

cpe:2.3:o:asus:prime_z270m-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-A Firmware by Asus

cpe:2.3:o:asus:h110m-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc847C Firmware by Siemens

Version Range Affected
To 6.2.61.3535 (exclusive)
cpe:2.3:o:siemens:simatic_ipc847c_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-C Firmware by Asus

cpe:2.3:o:asus:b150m-c_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B250M-F Plus Firmware by Asus

cpe:2.3:o:asus:b250m-f_plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc627C Firmware by Siemens

Version Range Affected
To 6.2.61.3535 (exclusive)
cpe:2.3:o:siemens:simatic_ipc627c_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-A\/M.2 Firmware by Asus

cpe:2.3:o:asus:b150m-a\/m.2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-Plus D3 Firmware by Asus

cpe:2.3:o:asus:b150m-plus_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

Version Range Affected
From 8.0.0.0 (inclusive)
To 8.1.71.3608 (inclusive)
cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Sinumerik Pcu50.5-C Firmware by Siemens

Version Range Affected
To 6.2.61.3535 (exclusive)
cpe:2.3:o:siemens:sinumerik_pcu50.5-c_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Manageability Engine Firmware by Intel

Version Range Affected
From 10.0.0.0 (inclusive)
To 10.0.55.3000 (inclusive)
cpe:2.3:o:intel:manageability_engine_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Z370-P Firmware by Asus

cpe:2.3:o:asus:prime_z370-p_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix H270I Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_h270i_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Viii Gene Firmware by Asus

cpe:2.3:o:asus:rog_maximus_viii_gene_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-H110M-V3 Firmware by Asus

cpe:2.3:o:asus:ex-h110m-v3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250M-Plus Firmware by Asus

cpe:2.3:o:asus:prime_b250m-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z370-I Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z370-i_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B250-S Firmware by Asus

cpe:2.3:o:asus:b250-s_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150I Pro Gaming\/Aura Firmware by Asus

cpe:2.3:o:asus:b150i_pro_gaming\/aura_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-B150M-V Firmware by Asus

cpe:2.3:o:asus:ex-b150m-v_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Z370-A Firmware by Asus

cpe:2.3:o:asus:prime_z370-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z270I Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z270i_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Ix Apex Firmware by Asus

cpe:2.3:o:asus:rog_maximus_ix_apex_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Viii Ranger Firmware by Asus

cpe:2.3:o:asus:rog_maximus_viii_ranger_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H170 Pro Gaming Firmware by Asus

cpe:2.3:o:asus:h170_pro_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H170-Pro Firmware by Asus

cpe:2.3:o:asus:h170-pro_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Trooper H110 D3 Firmware by Asus

cpe:2.3:o:asus:trooper_h110_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-A\/Dp Firmware by Asus

cpe:2.3:o:asus:h110m-a\/dp_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Itp1000 Firmware by Siemens

Version Range Affected
To 23.01.03 (exclusive)
cpe:2.3:o:siemens:simatic_itp1000_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus Ix Hero Firmware by Asus

cpe:2.3:o:asus:rog_maximus_ix_hero_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Sabertooth Z170 Mark 1 Firmware by Asus

cpe:2.3:o:asus:sabertooth_z170_mark_1_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime Z270-P Firmware by Asus

cpe:2.3:o:asus:prime_z270-p_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-B250M-V3 Firmware by Asus

cpe:2.3:o:asus:ex-b250m-v3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-D Firmware by Asus

cpe:2.3:o:asus:h110m-d_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-R Firmware by Asus

cpe:2.3:o:asus:h110m-r_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-H110M-V Firmware by Asus

cpe:2.3:o:asus:ex-h110m-v_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-B150-V7 Firmware by Asus

cpe:2.3:o:asus:ex-b150-v7_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Maximus X Formula Firmware by Asus

cpe:2.3:o:asus:rog_maximus_x_formula_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-Pro Firmware by Asus

cpe:2.3:o:asus:z170-pro_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-A D3 Firmware by Asus

cpe:2.3:o:asus:b150m-a_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110M-Ts Firmware by Asus

cpe:2.3:o:asus:h110m-ts_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Tuf Z270 Mark 2 Firmware by Asus

cpe:2.3:o:asus:tuf_z270_mark_2_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc847D Firmware by Siemens

Version Range Affected
To 9.1.41.3024 (exclusive)
cpe:2.3:o:siemens:simatic_ipc847d_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

H110S1 Firmware by Asus

cpe:2.3:o:asus:h110s1_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Q270-S Firmware by Asus

cpe:2.3:o:asus:q270-s_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Prime B250M-K Firmware by Asus

cpe:2.3:o:asus:prime_b250m-k_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc677C Firmware by Siemens

Version Range Affected
To 6.2.61.3535 (exclusive)
cpe:2.3:o:siemens:simatic_ipc677c_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-K Firmware by Asus

cpe:2.3:o:asus:b150m-k_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z270E Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z270e_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-A Firmware by Asus

cpe:2.3:o:asus:z170-a_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-Deluxe Firmware by Asus

cpe:2.3:o:asus:z170-deluxe_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z370-E Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z370-e_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150-Plus Firmware by Asus

cpe:2.3:o:asus:b150-plus_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150M-C D3 Firmware by Asus

cpe:2.3:o:asus:b150m-c_d3_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

B150 Pro Gaming Firmware by Asus

cpe:2.3:o:asus:b150_pro_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z370-F Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_z370-f_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix B250G Gaming Firmware by Asus

cpe:2.3:o:asus:rog_strix_b250g_gaming_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Ex-B250M-V5 Firmware by Asus

cpe:2.3:o:asus:ex-b250m-v5_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170 Pro Gaming\/Aura Firmware by Asus

cpe:2.3:o:asus:z170_pro_gaming\/aura_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Z170-P Firmware by Asus

cpe:2.3:o:asus:z170-p_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Simatic Ipc427E Firmware by Siemens

Version Range Affected
To 21.01.07 (exclusive)
cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System

Rog Strix Z270H Gaming\/K1 Firmware by Asus

cpe:2.3:o:asus:rog_strix_z270h_gaming\/k1_firmware:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdf
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&language…
https://security.netapp.com/advisory/ntap-20171120-0001/
https://www.asus.com/News/wzeltG5CjYaIwGJ0
http://www.securityfocus.com/bid/101918
Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/101918
http://www.securitytracker.com/id/1039852
Issue Tracking Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039852
https://cert-portal.siemens.com/productcert/pdf/ssa-892715.pdf
https://security-center.intel.com/advisory.aspx?intelid=INTEL-SA-00086&language…
https://security.netapp.com/advisory/ntap-20171120-0001/
https://www.asus.com/News/wzeltG5CjYaIwGJ0
http://www.securityfocus.com/bid/101918
Broken Link Third Party Advisory VDB Entry
http://www.securityfocus.com/bid/101918
http://www.securitytracker.com/id/1039852
Issue Tracking Third Party Advisory VDB Entry
http://www.securitytracker.com/id/1039852