Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-0860


The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.


Published

2014-07-07T11:01:28.680

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 5.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:N/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-310

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System ibm integrated_management_module_firmware ≤ 1.36 Yes
Hardware ibm integrated_management_module - Yes
Operating System ibm advanced_management_module_firmware ≤ 3.65 Yes
Hardware ibm advanced_management_module - Yes
Operating System ibm integrated_management_module_ii_firmware ≤ 3.65 Yes
Hardware ibm integrated_management_module_ii - Yes

References