CVE-2004-2600
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive…
Does this matter?
Lower severity and a low EPSS score (2.63%). Track it; it rarely justifies an emergency change on its own.
Description
The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.63% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- intel/cli auto-configuration utility · intel/client system setup utility · intel/server configuration wizard · intel/server control · intel/system setup utility · intel/carrier grade server tigpr2u · intel/carrier grade server tsrlt2 · intel/carrier grade server tsrmt2 · hp/carrier grade server cc2300 · hp/carrier grade server cc3300 · hp/carrier grade server cc3310 · intel/entry server board se7210tp1-e · intel/entry server platform sr1325tp1-e · intel/server board scb2 · intel/server board sds2 · intel/server board se7500wv2 · intel/server board se7501hg2 · intel/server board shg2 · intel/server platform spsh4 · intel/server platform sr870bh2 · +2 more
- Source
- cve@mitre.org
References
- ftp://download.intel.com/support/motherboards/server/sb/aa6791invalidlanconfiguration040504.pdfVendor Advisory
- http://secunia.com/advisories/11315Patch, Vendor Advisory
- http://support.intel.com/support/motherboards/server/sb/CS-010422.htm
- http://www.osvdb.org/4978
- http://www.securityfocus.com/bid/10068
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15775
- ftp://download.intel.com/support/motherboards/server/sb/aa6791invalidlanconfiguration040504.pdfVendor Advisory
- http://secunia.com/advisories/11315Patch, Vendor Advisory
- http://support.intel.com/support/motherboards/server/sb/CS-010422.htm
- http://www.osvdb.org/4978
- http://www.securityfocus.com/bid/10068
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15775
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.