Vulnerability Description
IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use this account to gain unauthorised access to the BMC. IBM X-Force ID: 168883.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ibm | Datapower Gateway | >= 7.6.0.0, <= 7.6.0.14 |
Related Weaknesses (CWE)
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/168883VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/1125615Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/168883VDB EntryVendor Advisory
- https://www.ibm.com/support/pages/node/1125615Vendor Advisory
FAQ
What is CVE-2019-4621?
CVE-2019-4621 is a vulnerability with a CVSS score of 9.8 (CRITICAL). IBM DataPower Gateway 7.6.0.0-7 throug 6.0.14 and 2018.4.1.0 through 2018.4.1.5 have a default administrator account that is enabled if the IPMI LAN channel is enabled. A remote attacker could use thi...
How severe is CVE-2019-4621?
CVE-2019-4621 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2019-4621?
Check the references section above for vendor advisories and patch information. Affected products include: Ibm Datapower Gateway.