ID

VAR-201308-0227


CVE

CVE-2013-4031


TITLE

plural IBM Operates on server products Integrated Management Module Vulnerable to performing power actions

Trust: 0.8

sources: JVNDB: JVNDB-2013-003697

DESCRIPTION

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers has a default password for the IPMI user account, which makes it easier for remote attackers to perform power-on, power-off, or reboot actions, or add or modify accounts, via unspecified vectors. System X3250 M4 is prone to a denial-of-service vulnerability

Trust: 1.98

sources: NVD: CVE-2013-4031 // JVNDB: JVNDB-2013-003697 // BID: 78033 // VULMON: CVE-2013-4031

AFFECTED PRODUCTS

vendor:ibmmodel:bladecenterscope:eqversion:hs22

Trust: 2.4

vendor:ibmmodel:bladecenterscope:eqversion:hs22v

Trust: 2.4

vendor:ibmmodel:bladecenterscope:eqversion:hs23

Trust: 2.4

vendor:ibmmodel:bladecenterscope:eqversion:hs23e

Trust: 2.4

vendor:ibmmodel:bladecenterscope:eqversion:hx5

Trust: 2.4

vendor:ibmmodel:flex system x220 compute nodescope:eqversion: -

Trust: 1.6

vendor:ibmmodel:flex system x240 compute nodescope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3200 m3scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3100 m4scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x idataplex dx360 m4 serverscope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3550 m2scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3550 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3250 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3530 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3500 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3650 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3500 m2scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3400 m2scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3550 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3620 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3630 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3250 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3850 x5scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3650 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3950 x5scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3400 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:flex system x440 compute nodescope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3500 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3650 m2scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3690 x5scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3630 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x idataplex dx360 m2 serverscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3750 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x idataplex dx360 m3 serverscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:flex system x220 compute nodescope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system x240 compute nodescope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system x440 compute nodescope: - version: -

Trust: 0.8

vendor:ibmmodel:system x idataplex dx360 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x idataplex dx360 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x idataplex dx360 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3100 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3200 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3250 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3250 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3400 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3400 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3500 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3500 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3500 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3530 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3550 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3550 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3550 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3620 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3630 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3630 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3650 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3650 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3650 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3690 x5scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3750 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3850 x5scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3950 x5scope: - version: -

Trust: 0.8

vendor:ibmmodel:systemscope:eqversion:x3950x5-

Trust: 0.3

vendor:ibmmodel:systemscope:eqversion:x3850x5-

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3750-

Trust: 0.3

vendor:ibmmodel:systemscope:eqversion:x3690x5-

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3650-

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3650-

Trust: 0.3

vendor:ibmmodel:system m2scope:eqversion:x3650-

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3630-

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3630-

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3620-

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3550-

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3550-

Trust: 0.3

vendor:ibmmodel:system m2scope:eqversion:x3550-

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3530-

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3500-

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3500-

Trust: 0.3

vendor:ibmmodel:system m2scope:eqversion:x3500-

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3400-

Trust: 0.3

vendor:ibmmodel:system m2scope:eqversion:x3400-

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3250-

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3250-

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3200-

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3100-

Trust: 0.3

vendor:ibmmodel:system idataplex dx360 m4 serverscope:eqversion:x-

Trust: 0.3

vendor:ibmmodel:system idataplex dx360 m3 serverscope:eqversion:x-

Trust: 0.3

vendor:ibmmodel:system idataplex dx360 m2 serverscope:eqversion:x-

Trust: 0.3

vendor:ibmmodel:flex system compute nodescope:eqversion:x440-

Trust: 0.3

vendor:ibmmodel:flex system compute nodescope:eqversion:x240-

Trust: 0.3

vendor:ibmmodel:flex system compute nodescope:eqversion:x220-

Trust: 0.3

vendor:ibmmodel:bladecenter hx5scope: - version: -

Trust: 0.3

vendor:ibmmodel:bladecenter hs23escope: - version: -

Trust: 0.3

vendor:ibmmodel:bladecenter hs23scope: - version: -

Trust: 0.3

vendor:ibmmodel:bladecenter hs22vscope: - version: -

Trust: 0.3

vendor:ibmmodel:bladecenter hs22scope: - version: -

Trust: 0.3

sources: BID: 78033 // JVNDB: JVNDB-2013-003697 // CNNVD: CNNVD-201308-142 // NVD: CVE-2013-4031

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2013-4031
value: HIGH

Trust: 1.8

CNNVD: CNNVD-201308-142
value: CRITICAL

Trust: 0.6

VULMON: CVE-2013-4031
value: HIGH

Trust: 0.1

VULMON: CVE-2013-4031
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.9

sources: VULMON: CVE-2013-4031 // JVNDB: JVNDB-2013-003697 // CNNVD: CNNVD-201308-142 // NVD: CVE-2013-4031

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.8

sources: JVNDB: JVNDB-2013-003697 // NVD: CVE-2013-4031

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201308-142

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-201308-142

CONFIGURATIONS

sources: NVD: CVE-2013-4031

PATCH

title:MIGR-5093463url:http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5093463

Trust: 0.8

sources: JVNDB: JVNDB-2013-003697

EXTERNAL IDS

db:NVDid:CVE-2013-4031

Trust: 2.8

db:XFid:86172

Trust: 0.9

db:JVNDBid:JVNDB-2013-003697

Trust: 0.8

db:XFid:20134031

Trust: 0.6

db:CNNVDid:CNNVD-201308-142

Trust: 0.6

db:BIDid:78033

Trust: 0.3

db:VULMONid:CVE-2013-4031

Trust: 0.1

sources: VULMON: CVE-2013-4031 // BID: 78033 // JVNDB: JVNDB-2013-003697 // CNNVD: CNNVD-201308-142 // NVD: CVE-2013-4031

REFERENCES

url:http://www.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5093463

Trust: 2.0

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/86172

Trust: 1.1

url:http://xforce.iss.net/xforce/xfdb/86172

Trust: 0.9

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-4031

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-4031

Trust: 0.8

url:https://cwe.mitre.org/data/definitions/255.html

Trust: 0.1

url:http://tools.cisco.com/security/center/viewalert.x?alertid=30356

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2013-4031 // BID: 78033 // JVNDB: JVNDB-2013-003697 // CNNVD: CNNVD-201308-142 // NVD: CVE-2013-4031

CREDITS

Unknown

Trust: 0.3

sources: BID: 78033

SOURCES

db:VULMONid:CVE-2013-4031
db:BIDid:78033
db:JVNDBid:JVNDB-2013-003697
db:CNNVDid:CNNVD-201308-142
db:NVDid:CVE-2013-4031

LAST UPDATE DATE

2022-05-04T10:27:21.327000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2013-4031date:2017-08-29T00:00:00
db:BIDid:78033date:2013-08-09T00:00:00
db:JVNDBid:JVNDB-2013-003697date:2013-08-13T00:00:00
db:CNNVDid:CNNVD-201308-142date:2013-08-14T00:00:00
db:NVDid:CVE-2013-4031date:2017-08-29T01:33:00

SOURCES RELEASE DATE

db:VULMONid:CVE-2013-4031date:2013-08-09T00:00:00
db:BIDid:78033date:2013-08-09T00:00:00
db:JVNDBid:JVNDB-2013-003697date:2013-08-13T00:00:00
db:CNNVDid:CNNVD-201308-142date:2013-08-14T00:00:00
db:NVDid:CVE-2013-4031date:2013-08-09T23:55:00