ID

VAR-201308-0229


CVE

CVE-2013-4037


TITLE

plural IBM Operates on server products Integrated Management Module Vulnerabilities that gain access

Trust: 0.8

sources: JVNDB: JVNDB-2013-003698

DESCRIPTION

The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack. Intelligent Platform Management Interface is prone to an authentication-bypass vulnerability. An attacker can exploit this issue to bypass the authentication mechanism and perform unauthorized actions on the affected computer. This may aid in further attacks

Trust: 1.89

sources: NVD: CVE-2013-4037 // JVNDB: JVNDB-2013-003698 // BID: 61884

AFFECTED PRODUCTS

vendor:ibmmodel:bladecenterscope:eqversion:hs22

Trust: 1.8

vendor:ibmmodel:bladecenterscope:eqversion:hs22v

Trust: 1.8

vendor:ibmmodel:bladecenterscope:eqversion:hs23

Trust: 1.8

vendor:ibmmodel:bladecenterscope:eqversion:hs23e

Trust: 1.8

vendor:ibmmodel:bladecenterscope:eqversion:hx5

Trust: 1.8

vendor:ibmmodel:system x3530 m4scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3500 m4scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3400 m2scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3500 m2scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3550 m2scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3400 m3scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3550 m4scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3550 m3scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3500 m3scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x3250 m4scope:eqversion: -

Trust: 1.6

vendor:ibmmodel:system x idataplex dx360 m4 serverscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:flex system x240 compute nodescope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3250 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3650 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:flex system x220 compute nodescope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3620 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3630 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3650 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:flex system x440 compute nodescope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3650 m2scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3690 x5scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3630 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3100 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3200 m3scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x idataplex dx360 m2 serverscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3850 x5scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3950 x5scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x3750 m4scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system x idataplex dx360 m3 serverscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:flex system x220 compute nodescope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system x240 compute nodescope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system x440 compute nodescope: - version: -

Trust: 0.8

vendor:ibmmodel:system x idataplex dx360 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x idataplex dx360 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x idataplex dx360 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3100 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3200 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3250 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3250 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3400 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3400 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3500 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3500 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3500 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3530 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3550 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3550 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3550 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3620 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3630 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3630 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3650 m2scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3650 m3scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3650 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3690 x5scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3750 m4scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3850 x5scope: - version: -

Trust: 0.8

vendor:ibmmodel:system x3950 x5scope: - version: -

Trust: 0.8

vendor:intelmodel:intelligent platform management interfacescope:eqversion:0

Trust: 0.3

vendor:ibmmodel:systemscope:eqversion:x3950x5

Trust: 0.3

vendor:ibmmodel:systemscope:eqversion:x3850x5

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3750

Trust: 0.3

vendor:ibmmodel:systemscope:eqversion:x3690x5

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3650

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3650

Trust: 0.3

vendor:ibmmodel:system m2scope:eqversion:x3650

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3630

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3630

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3620

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3550

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3550

Trust: 0.3

vendor:ibmmodel:system m2scope:eqversion:x3550

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3530

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3500

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3500

Trust: 0.3

vendor:ibmmodel:system m2scope:eqversion:x3500

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3400

Trust: 0.3

vendor:ibmmodel:system m2scope:eqversion:x3400

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3250

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3250

Trust: 0.3

vendor:ibmmodel:system m3scope:eqversion:x3200

Trust: 0.3

vendor:ibmmodel:system m4scope:eqversion:x3100

Trust: 0.3

vendor:ibmmodel:system idataplex dx360 m4scope:eqversion:x

Trust: 0.3

vendor:ibmmodel:system idataplex dx360 m3scope:eqversion:x

Trust: 0.3

vendor:ibmmodel:system idataplex dx360 m2scope:eqversion:x

Trust: 0.3

vendor:ibmmodel:integrated management modulescope:eqversion:0

Trust: 0.3

vendor:ibmmodel:flex system compute nodescope:eqversion:x440

Trust: 0.3

vendor:ibmmodel:flex system compute nodescope:eqversion:x240

Trust: 0.3

vendor:ibmmodel:flex system compute nodescope:eqversion:x220

Trust: 0.3

vendor:ibmmodel:bladecenter hx5scope: - version: -

Trust: 0.3

vendor:ibmmodel:bladecenter hs23escope: - version: -

Trust: 0.3

vendor:ibmmodel:bladecenter hs23scope: - version: -

Trust: 0.3

vendor:ibmmodel:bladecenter hs22vscope: - version: -

Trust: 0.3

vendor:ibmmodel:bladecenter hs22scope: - version: -

Trust: 0.3

sources: BID: 61884 // JVNDB: JVNDB-2013-003698 // CNNVD: CNNVD-201308-143 // NVD: CVE-2013-4037

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2013-4037
value: MEDIUM

Trust: 1.8

CNNVD: CNNVD-201308-143
value: MEDIUM

Trust: 0.6

NVD: CVE-2013-4037
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: NONE
impactScore: NONE
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2013-003698 // CNNVD: CNNVD-201308-143 // NVD: CVE-2013-4037

PROBLEMTYPE DATA

problemtype:NVD-CWE-noinfo

Trust: 1.0

sources: NVD: CVE-2013-4037

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201308-143

TYPE

Design Error

Trust: 0.3

sources: BID: 61884

CONFIGURATIONS

sources: NVD: CVE-2013-4037

PATCH

title:MIGR-5093463url:http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5093463

Trust: 0.8

sources: JVNDB: JVNDB-2013-003698

EXTERNAL IDS

db:NVDid:CVE-2013-4037

Trust: 2.7

db:JVNDBid:JVNDB-2013-003698

Trust: 0.8

db:XFid:86173

Trust: 0.6

db:XFid:20134037

Trust: 0.6

db:CNNVDid:CNNVD-201308-143

Trust: 0.6

db:BIDid:61884

Trust: 0.3

sources: BID: 61884 // JVNDB: JVNDB-2013-003698 // CNNVD: CNNVD-201308-143 // NVD: CVE-2013-4037

REFERENCES

url:http://www.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5093463

Trust: 1.6

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/86173

Trust: 1.0

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-4037

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-4037

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/86173

Trust: 0.6

url:http://www.ibm.com/

Trust: 0.3

url:http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5093463

Trust: 0.3

sources: BID: 61884 // JVNDB: JVNDB-2013-003698 // CNNVD: CNNVD-201308-143 // NVD: CVE-2013-4037

CREDITS

IBM

Trust: 0.3

sources: BID: 61884

SOURCES

db:BIDid:61884
db:JVNDBid:JVNDB-2013-003698
db:CNNVDid:CNNVD-201308-143
db:NVDid:CVE-2013-4037

LAST UPDATE DATE

2022-05-04T08:57:48.057000+00:00


SOURCES UPDATE DATE

db:BIDid:61884date:2013-08-20T00:00:00
db:JVNDBid:JVNDB-2013-003698date:2013-08-13T00:00:00
db:CNNVDid:CNNVD-201308-143date:2013-08-16T00:00:00
db:NVDid:CVE-2013-4037date:2017-08-29T01:33:00

SOURCES RELEASE DATE

db:BIDid:61884date:2013-08-20T00:00:00
db:JVNDBid:JVNDB-2013-003698date:2013-08-13T00:00:00
db:CNNVDid:CNNVD-201308-143date:2013-08-13T00:00:00
db:NVDid:CVE-2013-4037date:2013-08-09T23:55:00