MEDIUM · 5.0

CVE-2004-2600

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter,...

Vulnerability Description

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IntelCli Auto-Configuration UtilityAll versions
IntelClient System Setup UtilityAll versions
IntelServer Configuration WizardAll versions
IntelServer ControlAll versions
IntelSystem Setup UtilityAll versions
IntelCarrier Grade Server Tigpr2UAll versions
IntelCarrier Grade Server Tsrlt2All versions
IntelCarrier Grade Server Tsrmt2All versions
HpCarrier Grade Server Cc2300a6898a
HpCarrier Grade Server Cc3300a6900a
HpCarrier Grade Server Cc3310a9862a
IntelEntry Server Board Se7210Tp1-EAll versions
IntelEntry Server Platform Sr1325Tp1-EAll versions
IntelServer Board Scb2All versions
IntelServer Board Sds2All versions
IntelServer Board Se7500Wv2All versions
IntelServer Board Se7501Hg2All versions
IntelServer Board Shg2All versions
IntelServer Platform Spsh4All versions
IntelServer Platform Sr870Bh2All versions

References

FAQ

What is CVE-2004-2600?

CVE-2004-2600 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter,...

How severe is CVE-2004-2600?

CVE-2004-2600 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2004-2600?

Check the references section above for vendor advisories and patch information. Affected products include: Intel Cli Auto-Configuration Utility, Intel Client System Setup Utility, Intel Server Configuration Wizard, Intel Server Control, Intel System Setup Utility.