CVE-2013-4037
IBM BladeCenter and System x - Password Hash Exposure via RAKP Protocol
Title source: llmDescription
The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.
References (2)
Core 2
Core References
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5093463
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/86173
Scores
EPSS
0.0095
EPSS Percentile
57.8%
Details
Status
published
Products (34)
ibm/bladecenter
hs22
ibm/bladecenter
hs22v
ibm/bladecenter
hs23
ibm/bladecenter
hs23e
ibm/bladecenter
hx5
ibm/flex_system_x220_compute_node
ibm/flex_system_x240_compute_node
ibm/flex_system_x440_compute_node
ibm/system_x3100_m4
ibm/system_x3200_m3
... and 24 more
Published
Aug 09, 2013
Tracked Since
Feb 18, 2026