First published: Mon Jul 07 2014(Updated: )
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Integrated Management Module Firmware | <=1.36 | |
IBM Integrated Management Module | ||
Ibm Advanced Management Module Firmware | <=3.65 | |
Ibm Advanced Management Module | ||
Ibm Integrated Management Module Ii Firmware | <=3.65 | |
IBM Integrated Management Module II |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.