First published: Fri Apr 16 2010(Updated: )
The IBM BladeCenter with Advanced Management Module (AMM) firmware before bpet50g does not properly perform interrupt sharing for USB and iSCSI, which allows remote attackers to cause a denial of service (management module reboot) via TCP packets with malformed application data.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
IBM Advanced Management Module Firmware | <=2.50 | |
IBM Advanced Management Module Firmware | =1.00 | |
IBM Advanced Management Module Firmware | =1.01 | |
IBM Advanced Management Module Firmware | =1.20 | |
IBM Advanced Management Module Firmware | =1.20-f | |
IBM Advanced Management Module Firmware | =1.25 | |
IBM Advanced Management Module Firmware | =1.25-e | |
IBM Advanced Management Module Firmware | =1.25-i | |
IBM Advanced Management Module Firmware | =1.26-b | |
IBM Advanced Management Module Firmware | =1.26-e | |
IBM Advanced Management Module Firmware | =1.26-h | |
IBM Advanced Management Module Firmware | =1.26-i | |
IBM Advanced Management Module Firmware | =1.26-k | |
IBM Advanced Management Module Firmware | =1.28-g | |
IBM Advanced Management Module Firmware | =1.32-d | |
IBM Advanced Management Module Firmware | =1.34-b | |
IBM Advanced Management Module Firmware | =1.34-e | |
IBM Advanced Management Module Firmware | =1.36-d | |
IBM Advanced Management Module Firmware | =1.36-g | |
IBM Advanced Management Module Firmware | =1.36-h | |
IBM Advanced Management Module Firmware | =1.36-k | |
IBM Advanced Management Module Firmware | =1.42-d | |
IBM Advanced Management Module Firmware | =1.42-f | |
IBM Advanced Management Module Firmware | =1.42-i | |
IBM Advanced Management Module Firmware | =1.42-n | |
IBM Advanced Management Module Firmware | =1.42-o | |
IBM Advanced Management Module Firmware | =1.42-t | |
IBM Advanced Management Module Firmware | =2.46-c | |
IBM Advanced Management Module Firmware | =2.46-j | |
IBM Advanced Management Module Firmware | =2.48-c | |
IBM Advanced Management Module Firmware | =2.48-d | |
IBM Advanced Management Module Firmware | =2.48-g | |
IBM Advanced Management Module Firmware | =2.48-l | |
IBM Advanced Management Module Firmware | =2.48-n | |
IBM BladeCenter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2010-1460 is considered high due to the potential for remote attackers to cause a denial of service.
To fix CVE-2010-1460, update the IBM Advanced Management Module firmware to version bpet50g or later.
CVE-2010-1460 affects the IBM BladeCenter with Advanced Management Module with specific firmware versions before bpet50g.
CVE-2010-1460 allows remote attackers to perform a denial of service by sending malformed TCP packets.
Yes, CVE-2010-1460 has been documented as being exploitable by using specially crafted TCP packets to trigger a management module reboot.