Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-2188


IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.


Published

2012-08-06T16:55:03.260

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.2 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm power_hardware_management_console_firmware 7r3.5.0 Yes
Operating System ibm power_hardware_management_console_firmware 7r7.1.0 Yes
Operating System ibm power_hardware_management_console_firmware 7r7.2.0 Yes
Operating System ibm power_hardware_management_console_firmware 7r7.3.0 Yes
Operating System ibm systems_director_management__console_firmware 6r7.3.0 Yes

References