CVE-2014-0860: Medium severity ibm integrated management module ii firmware vulnerability
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0860?
CVE-2014-0860 is considered a high severity vulnerability due to the exposure of cleartext IPMI credentials.
How do I fix CVE-2014-0860?
To fix CVE-2014-0860, update the firmware to the latest versions as specified in the security advisory.
What devices are affected by CVE-2014-0860?
CVE-2014-0860 affects IBM BladeCenter Advanced Management Module, IBM Integrated Management Module, and IBM Integrated Management Module II.
What can attackers do if they exploit CVE-2014-0860?
If exploited, attackers can execute arbitrary commands on the affected systems due to access to cleartext IPMI credentials.
When was CVE-2014-0860 disclosed?
CVE-2014-0860 was disclosed in 2014, highlighting the vulnerabilities in earlier firmware versions.