PT-2014-6097 · Ibm · Ibm System Networking G8124+16
Publicado
2014-09-23
·
Atualizado
2015-11-27
·
CVE-2014-4752
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IBM System Networking G8052 versions prior to 7.9.10.0
IBM System Networking G8124 versions prior to 7.9.10.0
IBM System Networking G8124-E versions prior to 7.9.10.0
IBM System Networking G8124-ER versions prior to 7.9.10.0
IBM System Networking G8264 versions prior to 7.9.10.0
IBM System Networking G8316 versions prior to 7.9.10.0
IBM System Networking G8264-T versions prior to 7.9.10.0
EN4093 switches versions prior to 7.8.6.0
EN4093R switches versions prior to 7.8.6.0
CN4093 switches versions prior to 7.8.6.0
SI4093 switches versions prior to 7.8.6.0
EN2092 switches versions prior to 7.8.6.0
G8264CS switches versions prior to 7.8.6.0
Flex System Interconnect Fabric versions prior to 7.8.6.0
1G L2-7 SLB switch for Bladecenter versions prior to 21.0.21.0
10G VFSM for Bladecenter versions prior to 7.8.14.0
1:10G switch for Bladecenter versions prior to 7.4.8.0
1G switch for Bladecenter versions prior to 5.3.5.0
Server Connectivity Module versions prior to 1.1.3.4
System Networking RackSwitch G8332 versions prior to 7.7.17.0
System Networking RackSwitch G8000 versions prior to 7.1.7.0
Description
The issue is related to hardcoded credentials in the affected devices, which makes it easier for remote attackers to obtain access. The exact vectors used for the attack are not specified.
Recommendations
For IBM System Networking G8052, update to version 7.9.10.0 or later.
For IBM System Networking G8124, update to version 7.9.10.0 or later.
For IBM System Networking G8124-E, update to version 7.9.10.0 or later.
For IBM System Networking G8124-ER, update to version 7.9.10.0 or later.
For IBM System Networking G8264, update to version 7.9.10.0 or later.
For IBM System Networking G8316, update to version 7.9.10.0 or later.
For IBM System Networking G8264-T, update to version 7.9.10.0 or later.
For EN4093 switches, update to version 7.8.6.0 or later.
For EN4093R switches, update to version 7.8.6.0 or later.
For CN4093 switches, update to version 7.8.6.0 or later.
For SI4093 switches, update to version 7.8.6.0 or later.
For EN2092 switches, update to version 7.8.6.0 or later.
For G8264CS switches, update to version 7.8.6.0 or later.
For Flex System Interconnect Fabric, update to version 7.8.6.0 or later.
For 1G L2-7 SLB switch for Bladecenter, update to version 21.0.21.0 or later.
For 10G VFSM for Bladecenter, update to version 7.8.14.0 or later.
For 1:10G switch for Bladecenter, update to version 7.4.8.0 or later.
For 1G switch for Bladecenter, update to version 5.3.5.0 or later.
For Server Connectivity Module, update to version 1.1.3.4 or later.
For System Networking RackSwitch G8332, update to version 7.7.17.0 or later.
For System Networking RackSwitch G8000, update to version 7.1.7.0 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
10G Vfsm For Bladecenter
1:10G Switch For Bladecenter
1G L2-7 Slb Switch For Bladecenter
1G Switch For Bladecenter
En4093 Switches
En2092 Switches
En4093R Switches
Flex System Interconnect Fabric
G8264Cs Switches
Ibm System Networking G8052
Ibm System Networking G8124
Ibm System Networking G8264
Ibm System Networking G8316
Si4093 Switches
Server Connectivity Module
System Networking Rackswitch G8000
System Networking Rackswitch G8332