CVE-2014-0860
IBM IMM Firmware <1.36 & AMM Firmware <3.65 - Cleartext IPMI Credential Exposure
Title source: llmDescription
The firmware before 3.66E in IBM BladeCenter Advanced Management Module (AMM), the firmware before 1.43 in IBM Integrated Management Module (IMM), and the firmware before 4.15 in IBM Integrated Management Module II (IMM2) contains cleartext IPMI credentials, which allows attackers to execute arbitrary IPMI commands, and consequently establish a blade remote-control session, by leveraging access to (1) the chassis internal network or (2) the Ethernet-over-USB interface.
References (2)
Core 2
Core References
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90880
Vendor Advisory x_refsource_confirm
http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5095840
Scores
EPSS
0.0098
EPSS Percentile
58.7%
Details
CWE
CWE-310
Status
published
Products (6)
ibm/advanced_management_module
ibm/advanced_management_module_firmware
< 3.65
ibm/integrated_management_module
ibm/integrated_management_module_firmware
< 1.36
ibm/integrated_management_module_ii
ibm/integrated_management_module_ii_firmware
< 3.65
Published
Jul 07, 2014
Tracked Since
Feb 18, 2026