Lucene search

K
cveIbmCVE-2014-0860
HistoryJul 07, 2014 - 11:01 a.m.

CVE-2014-0860

2014-07-0711:01:28
CWE-310
ibm
web.nvd.nist.gov
36
ibm
bladecenter
security
firmware
vulnerability
cve-2014-0860
ipmi

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

48.6%

The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.

Affected configurations

Nvd
Node
ibmintegrated_management_module_firmwareRange1.36
AND
ibmintegrated_management_moduleMatch-
Node
ibmadvanced_management_module_firmwareRange3.65
AND
ibmadvanced_management_moduleMatch-
Node
ibmintegrated_management_module_ii_firmwareRange3.65
AND
ibmintegrated_management_module_iiMatch-
VendorProductVersionCPE
ibmintegrated_management_module_firmware*cpe:2.3:o:ibm:integrated_management_module_firmware:*:*:*:*:*:*:*:*
ibmintegrated_management_module-cpe:2.3:h:ibm:integrated_management_module:-:*:*:*:*:*:*:*
ibmadvanced_management_module_firmware*cpe:2.3:o:ibm:advanced_management_module_firmware:*:*:*:*:*:*:*:*
ibmadvanced_management_module-cpe:2.3:h:ibm:advanced_management_module:-:*:*:*:*:*:*:*
ibmintegrated_management_module_ii_firmware*cpe:2.3:o:ibm:integrated_management_module_ii_firmware:*:*:*:*:*:*:*:*
ibmintegrated_management_module_ii-cpe:2.3:h:ibm:integrated_management_module_ii:-:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

AI Score

7.3

Confidence

Low

EPSS

0.001

Percentile

48.6%

Related for CVE-2014-0860