First published: Fri Aug 09 2013(Updated: )
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information by reading a file.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM BladeCenter | =hs22 | |
IBM BladeCenter | =hs22v | |
IBM BladeCenter | =hs23 | |
IBM BladeCenter | =hs23e | |
IBM BladeCenter | =hx5 | |
Ibm Flex System X220 Compute Node | ||
Ibm Flex System X240 Compute Node | ||
Ibm Flex System X440 Compute Node | ||
Ibm System X Idataplex Dx360 M2 Server | ||
Ibm System X Idataplex Dx360 M3 Server | ||
Ibm System X Idataplex Dx360 M4 Server | ||
Ibm System X3100 M4 | ||
Ibm System X3200 M3 | ||
Ibm System X3250 M3 | ||
Ibm System X3250 M4 | ||
Ibm System X3400 M2 | ||
Ibm System X3400 M3 | ||
Ibm System X3500 M2 | ||
Ibm System X3500 M3 | ||
Ibm System X3500 M4 | ||
Ibm System X3530 M4 | ||
Ibm System X3550 M2 | ||
Ibm System X3550 M3 | ||
Ibm System X3550 M4 | ||
Ibm System X3620 M3 | ||
Ibm System X3630 M3 | ||
Ibm System X3630 M4 | ||
Ibm System X3650 M2 | ||
Ibm System X3650 M3 | ||
Ibm System X3650 M4 | ||
Ibm System X3690 X5 | ||
Ibm System X3750 M4 | ||
Ibm System X3850 X5 | ||
Ibm System X3950 X5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-4038 has a high severity rating due to its use of cleartext password storage, which exposes sensitive information.
To fix CVE-2013-4038, implement secure password storage and encryption mechanisms in the IPMI implementation.
CVE-2013-4038 affects various IBM products including BladeCenter, Flex System, and System x servers.
The risks of CVE-2013-4038 include unauthorized access to sensitive information and potential system control by attackers.
Yes, CVE-2013-4038 can be exploited remotely by attackers with network access to the affected IBM systems.