CVE-2014-0860

IBM IMM Firmware <1.36 & AMM Firmware <3.65 - Cleartext IPMI Credential Exposure

Title source: llm
STIX 2.1

Description

The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90880

Scores

EPSS 0.0098
EPSS Percentile 58.7%

Details

CWE
CWE-310
Status published
Products (6)
ibm/advanced_management_module
ibm/advanced_management_module_firmware < 3.65
ibm/integrated_management_module
ibm/integrated_management_module_firmware < 1.36
ibm/integrated_management_module_ii
ibm/integrated_management_module_ii_firmware < 3.65
Published Jul 07, 2014
Tracked Since Feb 18, 2026