First published: Fri Aug 09 2013(Updated: )
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BladeCenter | =hs22 | |
IBM BladeCenter | =hs22v | |
IBM BladeCenter | =hs23 | |
IBM BladeCenter | =hs23e | |
IBM BladeCenter | =hx5 | |
IBM Flex System X220 Compute Node | ||
IBM Flex System X240 | ||
IBM Flex System X440 | ||
Lenovo System X Idataplex Dx360 M2 Firmware | ||
IBM System X iDataPlex DX360 M3 Server | ||
IBM iDataplex Dx360 M4 | ||
Ibm System X3100 M4 Firmware | ||
IBM System X3200 M3 | ||
IBM System X3250 M3 | ||
IBM System X3250 M4 Firmware | ||
IBM System X3400 M2 | ||
Lenovo System X3400 M3 | ||
Lenovo System X3500 M2 | ||
Lenovo System X3500 M3 | ||
Lenovo System X3500 M4 Firmware | ||
Lenovo System X3530 M4 | ||
Lenovo System X3560 M2 | ||
Lenovo System X3550 M3 Firmware | ||
Lenovo System X3550 M4 | ||
IBM System X3620 M3 | ||
Lenovo System X3630 M3 | ||
Lenovo System X3630 M4 | ||
IBM System X3650 M2 | ||
Lenovo System X3650 M3 Firmware | ||
IBM System x3650 M4 Firmware | ||
Lenovo System X3690 X5 Firmware | ||
Lenovo System X3750 M4 | ||
Lenovo System X3850 X5 | ||
Lenovo System X3950 X5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4031 is considered a high-severity vulnerability due to the default password for the IPMI user account.
To mitigate CVE-2013-4031, change the default password for the IPMI user account immediately.
CVE-2013-4031 affects various IBM BladeCenter, Flex System, System x iDataPlex, and System x servers.
CVE-2013-4031 is a credential management vulnerability related to the default IPMI user account.
There are no specific reports of active exploitation of CVE-2013-4031, but the presence of a default password poses security risks.