CVE-2012-2188
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
IBM Power Hardware Management Console (HMC) 7R3.5.0 before SP4, 7R7.1.0 and 7R7.2.0 before 7R7.2.0 SP3, and 7R7.3.0 before SP2, and Systems Director Management Console (SDMC) 6R7.3.0 before SP2, does not properly restrict the VIOS viosrvcmd command, which allows local users to gain privileges via vectors involving a (1) $ (dollar sign) or (2) & (ampersand) character.
IBM Power Hardware Management Console (HMC) v7R3.5.0 anteriores a vSP4, v7R7.1.0 y 7R7.2.0 anteriores a v7R7.2.0 SP3, y 7R7.3.0 anteriores a SP2, y Systems Director Management Console (SDMC) v6R7.3.0 anteriores a SP2, no restringe de forma adecuada el comando VIOS viosrvcmd, lo que permite a usuarios locales a obtener privilegios a través de vectores que implican los caracteres (1) $ (signo del dolar) o (2) & (ampersand).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2012-04-04 CVE Reserved
- 2012-08-06 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/75906 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Power Hardware Management Console Firmware Search vendor "Ibm" for product "Power Hardware Management Console Firmware" | 7r3.5.0 Search vendor "Ibm" for product "Power Hardware Management Console Firmware" and version "7r3.5.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Power Hardware Management Console Firmware Search vendor "Ibm" for product "Power Hardware Management Console Firmware" | 7r7.1.0 Search vendor "Ibm" for product "Power Hardware Management Console Firmware" and version "7r7.1.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Power Hardware Management Console Firmware Search vendor "Ibm" for product "Power Hardware Management Console Firmware" | 7r7.2.0 Search vendor "Ibm" for product "Power Hardware Management Console Firmware" and version "7r7.2.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Power Hardware Management Console Firmware Search vendor "Ibm" for product "Power Hardware Management Console Firmware" | 7r7.3.0 Search vendor "Ibm" for product "Power Hardware Management Console Firmware" and version "7r7.3.0" | - |
Affected
| ||||||
Ibm Search vendor "Ibm" | Systems Director Management Console Firmware Search vendor "Ibm" for product "Systems Director Management Console Firmware" | 6r7.3.0 Search vendor "Ibm" for product "Systems Director Management Console Firmware" and version "6r7.3.0" | - |
Affected
|