CVE-2013-4031
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-255
- Affected
- ibm/bladecenter · ibm/flex system x220 compute node · ibm/flex system x240 compute node · ibm/flex system x440 compute node · ibm/system x idataplex dx360 m2 server · ibm/system x idataplex dx360 m3 server · ibm/system x idataplex dx360 m4 server · ibm/system x3100 m4 · ibm/system x3200 m3 · ibm/system x3250 m3 · ibm/system x3250 m4 · ibm/system x3400 m2 · ibm/system x3400 m3 · ibm/system x3500 m2 · ibm/system x3500 m3 · ibm/system x3500 m4 · ibm/system x3530 m4 · ibm/system x3550 m2 · ibm/system x3550 m3 · ibm/system x3550 m4 · +10 more
- Source
- psirt@us.ibm.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.