CISA KEV · catalog date Jan 28, 2022 · first observed Jul 19, 2026
Evidence dossier
CVE-2017-5689
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability…
Exploited in the wild (CISA KEV since Jan 28, 2022). NVD reports CVSS 3.1 9.8. EPSS estimates 92.2% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
- State
- PUBLISHED
- Published
- May 2, 2017
- Updated
- Oct 21, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAintelOriginal evidence ↗
Record text: An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
Inspect raw assertion
- Field
container- Value
- An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 92.19% probability · 99.81th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.921890000000; percentile 0.998140000000
FIRST EPSS · score date Aug 26, 2026 · 99.8th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
Inspect raw assertion
- Field
container- Value
- An unprivileged network attacker could gain system privileges to provisioned Intel manageability SKUs: Intel Active Management Technology (AMT) and Intel Standard Manageability (ISM). An unprivileged local attacker could provision manageability features gaining unprivileged network or local system privileges on Intel manageability SKUs: Intel Active Management Technology (AMT), Intel Standard Manageability (ISM), and Intel Small Business Technology (SBT).
Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability
92.19% probability · 99.81th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.921890000000; percentile 0.998140000000
Applicability
Cited product scope
Grouped from 79 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
72 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "fixed in versions 6.2.61.3535, 7.1.91.3272, 8.1.71.3608, 9.1.41.3024, 10.0.55.3000, 11.0.25.3001, and 11.6.27.3264 and later"}]product-d12aa20d337c825294c690f51ebf46fa7e5b06a6918449edff594c2f386f58ecLinked exactInspect raw assertion
cpe:2.3:h:hpe:proliant_ml10_gen9_server:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
64edac0b-39a9-41ff-99aa-66a4422efe53
product-5c35e15f334b4a6e2ed81492fddc595a6194453456191ad68e84ce7e804eeba6Linked exactInspect raw assertion
cpe:2.3:o:hpe:proliant_ml10_gen9_server_firmware:5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5abea07c-9e91-4937-9f6c-a687b2f946a1
product-371c14ceab769791894184c9f6d86c5d4f3baea6f84e3d7b0236adedfedfc022Linked exactInspect raw assertions
cpe:2.3:o:intel:active_management_technology_firmware:11.6:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
86388428-3285-4bc8-b0f2-2049b07711f0
cpe:2.3:o:intel:active_management_technology_firmware:7.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bd06fa87-e538-4492-9031-068ca05e63cb
cpe:2.3:o:intel:active_management_technology_firmware:11.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4b71755c-4b29-4947-a436-1658097cd3f6
cpe:2.3:o:intel:active_management_technology_firmware:10.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bf833cf3-0170-491d-aedb-33003b35b47b
cpe:2.3:o:intel:active_management_technology_firmware:6.2:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
eed42746-4191-4188-8bad-4a23b4d6b242
cpe:2.3:o:intel:active_management_technology_firmware:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
09936a93-41e2-4293-b88b-4b7ed4e6fd44
cpe:2.3:o:intel:active_management_technology_firmware:11.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6c27cd90-e986-4a89-b63e-1e3d2c62fbb3
cpe:2.3:o:intel:active_management_technology_firmware:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
52652be3-f695-42fb-a6ff-4a51dba6789b
cpe:2.3:o:intel:active_management_technology_firmware:8.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4290cdd9-8d27-46ad-befc-36827fa4a348
cpe:2.3:o:intel:active_management_technology_firmware:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bd4d2787-fa10-4b06-bc00-b869fb16a424
cpe:2.3:o:intel:active_management_technology_firmware:9.5:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7e92af85-322d-4587-b393-62172ea51d62
cpe:2.3:o:intel:active_management_technology_firmware:6.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c11d072b-b549-4352-b0e5-2e7c1923161e
cpe:2.3:o:intel:active_management_technology_firmware:9.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a8855e63-ae6c-44a7-a2fe-7e4791c69bd4
cpe:2.3:o:intel:active_management_technology_firmware:8.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 39 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cffaba0b-46e6-4f2b-ba13-a48bf2587f68
product-07d07705008f0ddba874bd946e8ada469d3ee1d8bd973c0a24058313474439e6Linked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_field_pg_m3:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 17 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
c6127c45-e91e-46b7-a806-fc0068575db5
product-5db4f261b4c1d8edf1cfc4451a1881fe246ebb258da5c30c83afac5cd9af4f77Linked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_field_pg_m3_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 17 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 6.2.61.3535
- Match ID
a15e9e54-0414-4c67-9dcd-181fcf2ee838
product-7757ee40377455f4a1171eb957f84a2791caa4301f0a056303b7a38190562c2dLinked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_field_pg_m4:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 18 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7adad919-32c1-49d2-a419-c9a803db6250
product-fdaa2692c23a8a7855ba0256a8659435f257444246e87f957be660d21f6db372Linked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_field_pg_m4_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 18 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 18.01.06
- Match ID
a4487a96-6af1-4f41-9ff7-ed711fb89fa4
product-80e4c9a99e10c91d4a7f0903f7320baf18ad610c1b17e32dab89943fe468361eLinked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_field_pg_m5:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 19 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
506dee00-30d2-4e29-9645-757eb8778c0f
product-3190e4ff429ff4e7982c2ba9e4470d0fbf172d1225032fc2be90c6322d36cd0fLinked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_field_pg_m5_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 19 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 22.01.03
- Match ID
8319d59a-6f4a-488d-b13f-90d70b448706
product-d5dc82cabcfcee030e37477267941cee59fceb4cc07fdfb9161ad7e3134c2a4dLinked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_ipc427d:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 35 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
46cc8afe-ed6c-4a50-ac80-d2309e03fae4
product-499c0a7fbc8de6ac45be4956744e2928242a2afd2b552b1afe01eec8fa6e734eLinked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_ipc427d_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 35 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a87041de-ea8d-4dc1-bd7c-03c42c6ee7fa
product-b6d1eed4f95284c38635e7d0d82dea53895bd6e9f37529b45ebd708e73d372f1Linked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_ipc427e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 36 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a40d0cdb-7be6-491f-b730-3b4e10ca159a
product-a709dcd9677729f0cbf4919109303ca2d3c6a11859c0cfdd21c617ed9f1eefbeLinked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_ipc427e_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 36 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 21.01.05
- Match ID
60a4f35f-96d5-4750-8597-5c4e74c690de
product-3a6b0a20d0bfdfd6131f52995ac95470d8eca718d919e6bef4130fdb9936daf4Linked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_ipc477d:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 16 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
754a6744-5194-4a99-bd3b-944a8707c80f
product-74d764317d05e5f83e66942cff1e21497b8bed863215767fb672d06fc8e42ca3Linked exactInspect raw assertions
cpe:2.3:o:siemens:simatic_ipc477d_firmware:-:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 16 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
bcc01671-a79a-423e-bd61-9056ae5cd240
cpe:2.3:o:siemens:simatic_ipc477d_firmware:-:*:*:*:pro:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 16 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4b4a9c1c-6105-455b-9639-7ee02af05b60
product-5becec834bdafa5042b37699d3e0967ecf929d1caf16eba0e21bb2ccb3113d1eLinked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_ipc477e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 15 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
fdf9d4c3-1892-48fa-95b4-835b636a4005
product-4e39e8dfd3bb917ce85f0ec5553b5c655336cff9268c644a18f9e6bad32b9c6eLinked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_ipc477e_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 15 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 21.01.05
- Match ID
7e311214-74e6-449f-a446-b14a498d85e9
product-09d748727cfa0850f02c16a6ef0c1096a9ad17b627ebeeabd2c194bffef91b92Linked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_ipc547d:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 14 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9dcf5972-c72d-4de9-8b73-3c497d54596b
product-eab938bbe0923bc8bbb2adcdf88a33b6b34be3afe412c5e70bf444d9e30d8d58Linked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_ipc547d_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 14 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 7.1.91.3272
- Match ID
42e364b9-1fc7-418a-860d-dd0e73dd930e
product-bb6f8df0d666042be414f83d6bd0cb4648b7f63c60feab522caf358efe2d56deLinked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_ipc547e:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 13 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d9dd4a97-1648-4c7f-a5a0-6899bd13a617
product-5c031f3d96479b560c57693611360a1cf7ab4524b6c1d046b73370137cab799fLinked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_ipc547e_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 9.1.41.3024
- Match ID
2cd389ce-aa26-445d-8d2b-27d3d06c3b68
product-dd80364fffb453ea6d0aa4f2dbbce18d97f3afd02be184e5d85f768d9b7b508eLinked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_ipc547g:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9eb339b5-602f-4ab5-9998-465fdc6abd6c
product-b481c414cde8a0ba23ad1017eed81b1dd7fc90f9abfaced79054513b86a2fd81Linked exactInspect raw assertion
cpe:2.3:o:siemens:simatic_ipc547g_firmware:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- through excluding 11.0.26.3000
- Match ID
124ed9b8-ba17-4204-bd5b-3f94558a6531
product-2c20dfa316edf36ff010f9ddfd9e06494930b9a956a8af049ad1bf3b41f5a2b8Linked exactInspect raw assertion
cpe:2.3:h:siemens:simatic_ipc627c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cd1a57a9-f6e5-4672-bd22-09ef5522ca10
Affected-product evidence
Accepted scope and product mapping
36 canonical links · 1 source-reported links
vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-0a633ff89453315e6508aef301ed49299b4bf95e5c03571bbdeee2991cf6d3ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
219f7835-9cc7-4d3f-9643-bf926f6c704evendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-0df67d19999ee937ae61a0b5a0d752d7b435c6dcc0b83d22dae9b0455e7a31f1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6f905978-3bfa-4a46-acc4-54459fdd8029c835615a-31ca-4dba-b076-c9930cc77933vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-1166036607f7b2db371d878b0057d0d9b4d637202f74c9123f08cc40f506b742
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
799211d7-8e01-46c1-9c3b-c45edf186720b10d1d75-f54d-4a3c-9492-826605a251afvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-214aa699f13c96e5f822682e9641d04a9b382a0d5dbfa0c14fabc73b28a2d371
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
22845eb1-6938-4db4-8d3d-93d0bec1420avendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-25be3437469665ca0bee7881809a1c72603aea3ae538a5273cbb2904368c9b91
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fbe8d252-ac25-4201-a779-8580dd44c27avendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-26c6816589acc96e8272bed48960fd865589a0a27e80bab96e1abd34fd46126e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
92a1a87a-5143-4fb1-aff0-9ce75b306881vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-3190e4ff429ff4e7982c2ba9e4470d0fbf172d1225032fc2be90c6322d36cd0f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1da2c3b8-c497-4919-8b45-1927ba0ec4aavendor-e8faba3c67dfadc7cd3f01f12d4fbb826b9cb97436643fb26fc87523829d78ed · product-371c14ceab769791894184c9f6d86c5d4f3baea6f84e3d7b0236adedfedfc022
- Source class
- Nvd cpe vulnerable target
- Assertions
- 14
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
06ebf1a9-c8f3-414c-abfa-101b48e2c48628ddb780-01c3-417e-9df8-1b2934508849571b47ed-a222-4f49-abed-d9348b1408a658540464-60d6-4644-9445-ce63eff3068d649bccb2-cdd0-48a0-b650-33f76b83fb8a8e45a944-d07d-4dc2-8ce2-71a04526321f9f976899-3e0f-4075-8351-26c3e0423ab2a6333883-71a1-42d9-bf29-9d32212e66b1b36f000d-87a3-4f45-9a8a-8e48129d42ffba1852a7-0f1b-48f3-8612-93a88750c18dbdcc6438-f9d9-4884-930f-543104a2763dbec22d52-5c97-469d-a542-3ab355ab3611eb5d5cf5-0afb-4e67-8083-3e628310d40bf33503cb-2e5c-405d-9bdf-f4b489344c07vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-3f7a59c0aeaf70567eb61a64d3ed158c908a26f27c9f8af4ec7416f414e1d103
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
20022943-340c-40f5-93e2-ef599451f0b6e122afa0-19cc-4d4c-9624-3ff252191974vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-3fa5df4497217c3f56419c38c179e3d2d96b173244222a13117f99bbc211664d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a53a8185-5206-4d55-bf91-9a030f908c41vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-43afe3bab2b34ed096780a2c7da5ab19bb5edd0802594a65daae3f146142ca59
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
80dd8b9d-064a-42a1-b181-5a5538736f80vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-499c0a7fbc8de6ac45be4956744e2928242a2afd2b552b1afe01eec8fa6e734e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7b569b5a-7a2c-4a24-a708-15548793ef1evendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-4e39e8dfd3bb917ce85f0ec5553b5c655336cff9268c644a18f9e6bad32b9c6e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
05a2b09e-3e2e-4ac9-b103-8d747c7d2ee1vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-5c031f3d96479b560c57693611360a1cf7ab4524b6c1d046b73370137cab799f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2b3268b7-fadf-4409-9bc6-56f089db6432vendor-fa9a2256de9595ebc844b3c5edd7c927e9848d0cf24747e2a09db25ef5ae1389 · product-5c35e15f334b4a6e2ed81492fddc595a6194453456191ad68e84ce7e804eeba6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c2be689a-de5e-4450-841a-736cc63e4a0fvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-5ce14c5bf21a3e2100837851de648769e853c27d4544b07f0d12d0ddecd0ed00
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5c2a308c-ecc0-4963-94dc-9473deffe18dvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-5db4f261b4c1d8edf1cfc4451a1881fe246ebb258da5c30c83afac5cd9af4f77
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5a02c4f4-5648-4e44-b0df-2250240a8577vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-619cc8a53c569e4271f68e5fb483239e4eb4158622a4aa1b8f1d2ef6702ae3a7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
518ae03c-f2af-4822-b608-3ca8cfd8ef00vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-74d764317d05e5f83e66942cff1e21497b8bed863215767fb672d06fc8e42ca3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0fc3c3a7-3c14-4b2b-a202-7c8e052216ffcaf09bea-ebb9-4ca0-8248-572def198037vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-8d5b22320596edca4912bfaa2c3a1b0a045f4e75a30e553452dfde5651f0e8b9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
91cf3cde-ac03-46e6-87c7-d0ca7df0cbb9vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9bd465eeca00b74161df9c5a4e2c242195389e9ef000e1dbe1d36936792f484f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
523849f5-9b61-4a7e-b22f-544f17700e80vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-9cd0ac76d4cf4fd452270d275fd866904f0ae73da085b72982499b6f7db84e58
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5fe1b3d2-1bb4-4132-9f2d-3582489ad734vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-a709dcd9677729f0cbf4919109303ca2d3c6a11859c0cfdd21c617ed9f1eefbe
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5b8204ee-97ec-40a8-9edb-8e7e3eeade31vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b481c414cde8a0ba23ad1017eed81b1dd7fc90f9abfaced79054513b86a2fd81
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3fe9f2ba-ecaa-410d-b1f0-b3c05161cbf3vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b5324e3481317a4552c5ca87765b743ce010fb4207fa29ac77b4e007c64093d9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
759d62c3-b3d8-4b99-895e-20ac4c332e5dvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b748deadd324e58693a9fbea9dcbbd49b73beaab4e2d3b75b492d69395713a8f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2309e12c-f535-496b-bb5d-4d2d7e460dcbvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-b96622e089609401d18aa78bed8715120d2267dc7e863ec8c5a55ec18b2b3679
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4819a168-555d-40fb-b197-71aaa59dc15677f86523-e866-4c27-8e7f-4ce4125239e7vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ba8eee6988a50f73dba28e7c3485bc59ad0ba8e4de09fd9fe884bdd6ab870ede
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
843fca4a-be05-40be-b8f0-30f7fc84db6avendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-dbf1ee25c8b364d84a32e276589de6f818225c9db075f58cb6c37073b5010817
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e0b3c4ac-d547-45ba-a95a-042591df4103vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ddd193245f2727db06abe9bb5f27384cea126d85b121ff92b52f13702032617f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a85805dd-106e-4fec-b246-0ce094bcd2aevendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ea29665a68a37b879b549cba74066ddc4d81dc0ee50df145683c43f3458269e0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
288ad63d-7e88-4e5b-af48-f5fc32636e6cvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-eab938bbe0923bc8bbb2adcdf88a33b6b34be3afe412c5e70bf444d9e30d8d58
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2f212daa-30e9-4388-bfd8-ae53bc71a183vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ebd5db1a62397ea2360b8d03bc7c020430abd6545368c2bc42fac9325b8325f1
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
749e3c56-2665-44c5-a230-a10370eaf8d8vendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-ed23c5d1e7859f8c6b217460c357475787704888fe76fb91f95efd826f898d75
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
838150ed-9251-4f14-8828-1cfc61e4ff4bvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-f266db4531bd8f89eec14e17f416f1d6816b3d295f0096f88b24dd0fc8ad3d1d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c88ad607-3995-46da-a74f-f98afdabb62dvendor-380ffb64c552a4e30b7eb6825ecde41bb36260544f33f7a0e7a01d1608acb38b · product-fdaa2692c23a8a7855ba0256a8659435f257444246e87f957be660d21f6db372
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5bc4fd0c-001a-4b24-b995-69b72c99b849Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cb689836-2243-4363-a248-031da9efdcd4Assessments
CVSS by origin
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HAV:N/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 9.8
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.