Lucene search

K
cveCertccCVE-2014-2955
HistoryJul 14, 2014 - 9:55 p.m.

CVE-2014-2955

2014-07-1421:55:05
CWE-287
certcc
web.nvd.nist.gov
37
cve-2014-2955
raritan px
authentication bypass
ipmi
remote attackers

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

Low

EPSS

0.006

Percentile

77.9%

Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.

Affected configurations

Nvd
Node
raritanpxRange1.5.8
OR
raritanpxMatch1.0
OR
raritanpxMatch1.0.4
OR
raritanpxMatch1.1
OR
raritanpxMatch1.1.6
OR
raritanpxMatch1.2
OR
raritanpxMatch1.2.5
OR
raritanpxMatch1.2.7
OR
raritanpxMatch1.3
OR
raritanpxMatch1.3.1
OR
raritanpxMatch1.3.5
OR
raritanpxMatch1.4.1
OR
raritanpxMatch1.5
OR
raritanpxMatch1.5.4
OR
raritanpxMatch1.5.7
AND
raritandpxr20a-16Match-
VendorProductVersionCPE
raritanpx*cpe:2.3:o:raritan:px:*:*:*:*:*:*:*:*
raritanpx1.0cpe:2.3:o:raritan:px:1.0:*:*:*:*:*:*:*
raritanpx1.0.4cpe:2.3:o:raritan:px:1.0.4:*:*:*:*:*:*:*
raritanpx1.1cpe:2.3:o:raritan:px:1.1:*:*:*:*:*:*:*
raritanpx1.1.6cpe:2.3:o:raritan:px:1.1.6:*:*:*:*:*:*:*
raritanpx1.2cpe:2.3:o:raritan:px:1.2:*:*:*:*:*:*:*
raritanpx1.2.5cpe:2.3:o:raritan:px:1.2.5:*:*:*:*:*:*:*
raritanpx1.2.7cpe:2.3:o:raritan:px:1.2.7:*:*:*:*:*:*:*
raritanpx1.3cpe:2.3:o:raritan:px:1.3:*:*:*:*:*:*:*
raritanpx1.3.1cpe:2.3:o:raritan:px:1.3.1:*:*:*:*:*:*:*
Rows per page:
1-10 of 161

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

AI Score

8.2

Confidence

Low

EPSS

0.006

Percentile

77.9%

Related for CVE-2014-2955