CVE-2013-4037: Medium severity IBM BladeCenter vulnerability
The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4037?
CVE-2013-4037 is rated as having moderate severity due to its impact on password protection for the RAKP protocol in IPMI implementations.
How do I fix CVE-2013-4037?
To fix CVE-2013-4037, apply the relevant patches and updates provided by IBM for affected BladeCenter and System x servers.
What systems are affected by CVE-2013-4037?
CVE-2013-4037 affects IBM BladeCenter, Flex System, iDataPlex, and various System x servers, including specific models like hs22, hx5, and more.
What is the nature of the vulnerability in CVE-2013-4037?
The vulnerability in CVE-2013-4037 involves sending a password hash to the client during authentication, which can lead to potential password exposure.
Has CVE-2013-4037 been mitigated?
Yes, mitigation for CVE-2013-4037 has been implemented through firmware updates from IBM that address the issues in the IPMI RAKP protocol.