Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-4031


The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors.


Published

2013-08-09T23:55:02.840

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 10.0 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-255

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Hardware ibm bladecenter hs22 Yes
Hardware ibm bladecenter hs22v Yes
Hardware ibm bladecenter hs23 Yes
Hardware ibm bladecenter hs23e Yes
Hardware ibm bladecenter hx5 Yes
Hardware ibm flex_system_x220_compute_node - Yes
Hardware ibm flex_system_x240_compute_node - Yes
Hardware ibm flex_system_x440_compute_node - Yes
Hardware ibm system_x_idataplex_dx360_m2_server - Yes
Hardware ibm system_x_idataplex_dx360_m3_server - Yes
Hardware ibm system_x_idataplex_dx360_m4_server - Yes
Hardware ibm system_x3100_m4 - Yes
Hardware ibm system_x3200_m3 - Yes
Hardware ibm system_x3250_m3 - Yes
Hardware ibm system_x3250_m4 - Yes
Hardware ibm system_x3400_m2 - Yes
Hardware ibm system_x3400_m3 - Yes
Hardware ibm system_x3500_m2 - Yes
Hardware ibm system_x3500_m3 - Yes
Hardware ibm system_x3500_m4 - Yes
Hardware ibm system_x3530_m4 - Yes
Hardware ibm system_x3550_m2 - Yes
Hardware ibm system_x3550_m3 - Yes
Hardware ibm system_x3550_m4 - Yes
Hardware ibm system_x3620_m3 - Yes
Hardware ibm system_x3630_m3 - Yes
Hardware ibm system_x3630_m4 - Yes
Hardware ibm system_x3650_m2 - Yes
Hardware ibm system_x3650_m3 - Yes
Hardware ibm system_x3650_m4 - Yes
Hardware ibm system_x3690_x5 - Yes
Hardware ibm system_x3750_m4 - Yes
Hardware ibm system_x3850_x5 - Yes
Hardware ibm system_x3950_x5 - Yes

References