First published: Fri Aug 09 2013(Updated: )
The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BladeCenter | =hs22 | |
IBM BladeCenter | =hs22v | |
IBM BladeCenter | =hs23 | |
IBM BladeCenter | =hs23e | |
IBM BladeCenter | =hx5 | |
IBM Flex System X220 Compute Node | ||
IBM Flex System X240 | ||
IBM Flex System X440 | ||
Lenovo System X Idataplex Dx360 M2 Firmware | ||
IBM System X iDataPlex DX360 M3 Server | ||
IBM iDataplex Dx360 M4 | ||
Ibm System X3100 M4 Firmware | ||
IBM System X3200 M3 | ||
IBM System X3250 M3 | ||
IBM System X3250 M4 Firmware | ||
IBM System X3400 M2 | ||
Lenovo System X3400 M3 | ||
Lenovo System X3500 M2 | ||
Lenovo System X3500 M3 | ||
Lenovo System X3500 M4 Firmware | ||
Lenovo System X3530 M4 | ||
Lenovo System X3560 M2 | ||
Lenovo System X3550 M3 Firmware | ||
Lenovo System X3550 M4 | ||
IBM System X3620 M3 | ||
Lenovo System X3630 M3 | ||
Lenovo System X3630 M4 | ||
IBM System X3650 M2 | ||
Lenovo System X3650 M3 Firmware | ||
IBM System x3650 M4 Firmware | ||
Lenovo System X3690 X5 Firmware | ||
Lenovo System X3750 M4 | ||
Lenovo System X3850 X5 | ||
Lenovo System X3950 X5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4037 is rated as having moderate severity due to its impact on password protection for the RAKP protocol in IPMI implementations.
To fix CVE-2013-4037, apply the relevant patches and updates provided by IBM for affected BladeCenter and System x servers.
CVE-2013-4037 affects IBM BladeCenter, Flex System, iDataPlex, and various System x servers, including specific models like hs22, hx5, and more.
The vulnerability in CVE-2013-4037 involves sending a password hash to the client during authentication, which can lead to potential password exposure.
Yes, mitigation for CVE-2013-4037 has been implemented through firmware updates from IBM that address the issues in the IPMI RAKP protocol.