CVE-2013-4037

IBM BladeCenter and System x - Password Hash Exposure via RAKP Protocol

Title source: llm
STIX 2.1

Description

The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/86173

Scores

EPSS 0.0095
EPSS Percentile 57.8%

Details

Status published
Products (34)
ibm/bladecenter hs22
ibm/bladecenter hs22v
ibm/bladecenter hs23
ibm/bladecenter hs23e
ibm/bladecenter hx5
ibm/flex_system_x220_compute_node
ibm/flex_system_x240_compute_node
ibm/flex_system_x440_compute_node
ibm/system_x3100_m4
ibm/system_x3200_m3
... and 24 more
Published Aug 09, 2013
Tracked Since Feb 18, 2026