Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2012-4856


The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors.


Security Impact Summary

CVE-2012-4856 is a security vulnerability that . Impacting 2 products from ibm, from ibm organizations running these solutions should prioritize assessment and patching.

Historical Context

Documented in 2012, this vulnerability occurred amid the cloud computing expansion era, where traditional network perimeter security models were being reevaluated. Organizations were transitioning from isolated infrastructure to interconnected systems, creating new attack surfaces that vulnerabilities like this could exploit.


Published

2012-12-20T12:02:18.200

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.9 (HIGH)

CVSSv2 Vector

AV:A/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

5.5

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm power_5_system_firmware ≤ sf240_418 Yes
Operating System ibm power_5_system_firmware sf240_201_201 Yes
Operating System ibm power_5_system_firmware sf240_202_201 Yes
Operating System ibm power_5_system_firmware sf240_219_201 Yes
Operating System ibm power_5_system_firmware sf240_222_201 Yes
Operating System ibm power_5_system_firmware sf240_233_201 Yes
Operating System ibm power_5_system_firmware sf240_258_201 Yes
Operating System ibm power_5_system_firmware sf240_259_201 Yes
Operating System ibm power_5_system_firmware sf240_261_201 Yes
Operating System ibm power_5_system_firmware sf240_284_201 Yes
Operating System ibm power_5_system_firmware sf240_298_201 Yes
Operating System ibm power_5_system_firmware sf240_299_201 Yes
Operating System ibm power_5_system_firmware sf240_320_201 Yes
Operating System ibm power_5_system_firmware sf240_332_201 Yes
Operating System ibm power_5_system_firmware sf240_338_201 Yes
Operating System ibm power_5_system_firmware sf240_358_201 Yes
Operating System ibm power_5_system_firmware sf240_371 Yes
Operating System ibm power_5_system_firmware sf240_382_382 Yes
Operating System ibm power_5_system_firmware sf240_403_382 Yes
Operating System ibm power_5_system_firmware sf240_415_382 Yes
Operating System ibm power_5_system_firmware sf240_417 Yes
Hardware ibm power_5 9110-51a Yes
Hardware ibm power_5 9110-510 Yes
Hardware ibm power_5 9111-285 Yes
Hardware ibm power_5 9111-520 Yes
Hardware ibm power_5 9113-550 Yes
Hardware ibm power_5 9115-505 Yes
Hardware ibm power_5 9116-561 Yes
Hardware ibm power_5 9117-570 Yes
Hardware ibm power_5 9118-575 Yes
Hardware ibm power_5 9123-710 Yes
Hardware ibm power_5 9124-720 Yes
Hardware ibm power_5 9131-52a Yes
Hardware ibm power_5 9133-55a Yes
Hardware ibm power_5 9405-520 Yes
Hardware ibm power_5 9406-520 Yes
Hardware ibm power_5 9406-525 Yes
Hardware ibm power_5 9406-550 Yes
Hardware ibm power_5 9406-570 Yes
Hardware ibm power_5 9407-515 Yes

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For ibm's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.