5
CVSSv2

CVE-2014-0860

Published: 07/07/2014 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

The firmware prior to 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware prior to 1.43 in IBM Integrated Management Module (IMM), and the firmware prior to 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows malicious users to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.

Vulnerable Product Search on Vulmon Subscribe to Product

ibm integrated_management_module_firmware

ibm integrated_management_module -

ibm advanced_management_module_firmware

ibm advanced_management_module -

ibm integrated_management_module_ii_firmware

ibm integrated_management_module_ii -