// For flags

CVE-2014-0860

 

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.

El firmware anterior a 3.66E en IBM BladeCenter Advanced Management Module (AMM), el firmware anterior a 1.43 en IBM Integrated Management Module (IMM), y el firmware anterior a 4.15 en IBM Integrated Management Module II (IMM2) contiene los credenciales IPMI en texto claro, lo que permite a atacantes remotos ejecutar comandos IPMI arbitrarios, y como consecuencia establecer una sesiĆ³n de control remoto blade, mediante el aprovechamiento del acceso a (1) el chassis internal network o (2) la interfaz 'Ethernet-over-USB'.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-01-06 CVE Reserved
  • 2014-07-07 CVE Published
  • 2023-03-07 EPSS Updated
  • 2024-08-06 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-310: Cryptographic Issues
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Ibm
Search vendor "Ibm"
Integrated Management Module Firmware
Search vendor "Ibm" for product "Integrated Management Module Firmware"
<= 1.36
Search vendor "Ibm" for product "Integrated Management Module Firmware" and version " <= 1.36"
-
Affected
in Ibm
Search vendor "Ibm"
Integrated Management Module
Search vendor "Ibm" for product "Integrated Management Module"
--
Affected
Ibm
Search vendor "Ibm"
Advanced Management Module Firmware
Search vendor "Ibm" for product "Advanced Management Module Firmware"
<= 3.65
Search vendor "Ibm" for product "Advanced Management Module Firmware" and version " <= 3.65"
-
Affected
in Ibm
Search vendor "Ibm"
Advanced Management Module
Search vendor "Ibm" for product "Advanced Management Module"
--
Affected
Ibm
Search vendor "Ibm"
Integrated Management Module Ii Firmware
Search vendor "Ibm" for product "Integrated Management Module Ii Firmware"
<= 3.65
Search vendor "Ibm" for product "Integrated Management Module Ii Firmware" and version " <= 3.65"
-
Affected
in Ibm
Search vendor "Ibm"
Integrated Management Module Ii
Search vendor "Ibm" for product "Integrated Management Module Ii"
--
Affected