PT-2015-4496 · Ibm · Ibm Powervc Standard
Published
2015-03-24
·
Updated
2015-03-24
·
CVE-2015-0137
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
IBM PowerVC Standard versions 1.2.0.x through 1.2.0.3
IBM PowerVC Standard versions 1.2.1.x through 1.2.1.x
Description
The issue allows man-in-the-middle attackers to spoof devices via a crafted certificate, as the validation of Hardware Management Console (HMC) certificates only occurs during the pre-login stage.
Recommendations
For IBM PowerVC Standard versions 1.2.0.x through 1.2.0.3, update to version 1.2.0.4 or later.
For IBM PowerVC Standard versions 1.2.1.x through 1.2.1.x, update to version 1.2.2 or later.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Powervc Standard