Lucene search

K
cve[email protected]CVE-2013-4031
HistoryAug 09, 2013 - 11:55 p.m.

CVE-2013-4031

2013-08-0923:55:02
CWE-255
web.nvd.nist.gov
29
ibm
servers
ipmi
default password
vulnerability
remote attack

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.1%

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors.

Affected configurations

NVD
Node
ibmbladecenterMatchhs22
OR
ibmbladecenterMatchhs22v
OR
ibmbladecenterMatchhs23
OR
ibmbladecenterMatchhs23e
OR
ibmbladecenterMatchhx5
OR
ibmflex_system_x220_compute_nodeMatch-
OR
ibmflex_system_x240_compute_nodeMatch-
OR
ibmflex_system_x440_compute_nodeMatch-
OR
ibmsystem_x_idataplex_dx360_m2_serverMatch-
OR
ibmsystem_x_idataplex_dx360_m3_serverMatch-
OR
ibmsystem_x_idataplex_dx360_m4_serverMatch-
OR
ibmsystem_x3100_m4Match-
OR
ibmsystem_x3200_m3Match-
OR
ibmsystem_x3250_m3Match-
OR
ibmsystem_x3250_m4Match-
OR
ibmsystem_x3400_m2Match-
OR
ibmsystem_x3400_m3Match-
OR
ibmsystem_x3500_m2Match-
OR
ibmsystem_x3500_m3Match-
OR
ibmsystem_x3500_m4Match-
OR
ibmsystem_x3530_m4Match-
OR
ibmsystem_x3550_m2Match-
OR
ibmsystem_x3550_m3Match-
OR
ibmsystem_x3550_m4Match-
OR
ibmsystem_x3620_m3Match-
OR
ibmsystem_x3630_m3Match-
OR
ibmsystem_x3630_m4Match-
OR
ibmsystem_x3650_m2Match-
OR
ibmsystem_x3650_m3Match-
OR
ibmsystem_x3650_m4Match-
OR
ibmsystem_x3690_x5Match-
OR
ibmsystem_x3750_m4Match-
OR
ibmsystem_x3850_x5Match-
OR
ibmsystem_x3950_x5Match-

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

76.1%

Related for CVE-2013-4031