First published: Mon Jul 07 2014(Updated: )
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
Ibm Integrated Management Module Firmware | <=1.36 | |
IBM Integrated Management Module | ||
Ibm Advanced Management Module Firmware | <=3.65 | |
Ibm Advanced Management Module | ||
Ibm Integrated Management Module Ii Firmware | <=3.65 | |
IBM Integrated Management Module II |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-0860 is considered a high severity vulnerability due to the exposure of cleartext IPMI credentials.
To fix CVE-2014-0860, update the firmware to the latest versions as specified in the security advisory.
CVE-2014-0860 affects IBM BladeCenter Advanced Management Module, IBM Integrated Management Module, and IBM Integrated Management Module II.
If exploited, attackers can execute arbitrary commands on the affected systems due to access to cleartext IPMI credentials.
CVE-2014-0860 was disclosed in 2014, highlighting the vulnerabilities in earlier firmware versions.