MEDIUM · 4.0

CVE-2013-4038

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext f...

Vulnerability Description

The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information by reading a file.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
IbmBladecenterhs22
IbmFlex System X220 Compute Node-
IbmFlex System X240 Compute Node-
IbmFlex System X440 Compute Node-
IbmSystem X Idataplex Dx360 M2 Server-
IbmSystem X Idataplex Dx360 M3 Server-
IbmSystem X Idataplex Dx360 M4 Server-
IbmSystem X3100 M4-
IbmSystem X3200 M3-
IbmSystem X3250 M3-
IbmSystem X3250 M4-
IbmSystem X3400 M2-
IbmSystem X3400 M3-
IbmSystem X3500 M2-
IbmSystem X3500 M3-
IbmSystem X3500 M4-
IbmSystem X3530 M4-
IbmSystem X3550 M2-
IbmSystem X3550 M3-
IbmSystem X3550 M4-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2013-4038?

CVE-2013-4038 is a vulnerability with a CVSS score of 4.0 (MEDIUM). The Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers uses cleartext f...

How severe is CVE-2013-4038?

CVE-2013-4038 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-4038?

Check the references section above for vendor advisories and patch information. Affected products include: Ibm Bladecenter, Ibm Flex System X220 Compute Node, Ibm Flex System X240 Compute Node, Ibm Flex System X440 Compute Node, Ibm System X Idataplex Dx360 M2 Server.