CVE-2014-0860
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.
El firmware anterior a 3.66E en IBM BladeCenter Advanced Management Module (AMM), el firmware anterior a 1.43 en IBM Integrated Management Module (IMM), y el firmware anterior a 4.15 en IBM Integrated Management Module II (IMM2) contiene los credenciales IPMI en texto claro, lo que permite a atacantes remotos ejecutar comandos IPMI arbitrarios, y como consecuencia establecer una sesiĆ³n de control remoto blade, mediante el aprovechamiento del acceso a (1) el chassis internal network o (2) la interfaz 'Ethernet-over-USB'.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-01-06 CVE Reserved
- 2014-07-07 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-310: Cryptographic Issues
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/90880 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095840 | 2017-08-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Ibm Search vendor "Ibm" | Integrated Management Module Firmware Search vendor "Ibm" for product "Integrated Management Module Firmware" | <= 1.36 Search vendor "Ibm" for product "Integrated Management Module Firmware" and version " <= 1.36" | - |
Affected
| in | Ibm Search vendor "Ibm" | Integrated Management Module Search vendor "Ibm" for product "Integrated Management Module" | - | - |
Affected
|
Ibm Search vendor "Ibm" | Advanced Management Module Firmware Search vendor "Ibm" for product "Advanced Management Module Firmware" | <= 3.65 Search vendor "Ibm" for product "Advanced Management Module Firmware" and version " <= 3.65" | - |
Affected
| in | Ibm Search vendor "Ibm" | Advanced Management Module Search vendor "Ibm" for product "Advanced Management Module" | - | - |
Affected
|
Ibm Search vendor "Ibm" | Integrated Management Module Ii Firmware Search vendor "Ibm" for product "Integrated Management Module Ii Firmware" | <= 3.65 Search vendor "Ibm" for product "Integrated Management Module Ii Firmware" and version " <= 3.65" | - |
Affected
| in | Ibm Search vendor "Ibm" | Integrated Management Module Ii Search vendor "Ibm" for product "Integrated Management Module Ii" | - | - |
Affected
|