The firmware prior to 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware prior to 1.43 in IBM Integrated Management Module (IMM), and the firmware prior to 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows malicious users to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ibm integrated_management_module_firmware |
||
ibm integrated_management_module - |
||
ibm advanced_management_module_firmware |
||
ibm advanced_management_module - |
||
ibm integrated_management_module_ii_firmware |
||
ibm integrated_management_module_ii - |