Vulnerability CVE-2014-0860


Published: 2014-07-07

Description:
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.

Type:

CWE-310

(Cryptographic Issues)

CVSS2 => (AV:N/AC:L/Au:N/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None
Affected software
IBM -> Advanced management module 
IBM -> Integrated management module 
IBM -> Integrated management module ii 
IBM -> Advanced management module firmware 
IBM -> Integrated management module firmware 
IBM -> Integrated management module ii firmware 

 References:
http://xforce.iss.net/xforce/xfdb/90880
http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095840

Copyright 2024, cxsecurity.com

 

Back to Top