PT-2019-17143 · Ibm · Ibm Datapower Gateway

Published

2019-12-09

·

Updated

2019-12-17

·

CVE-2019-4621

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions IBM DataPower Gateway versions 6.0.0 through 6.0.14 IBM DataPower Gateway versions 7.6.0.0 through 7.6.0 (no end version specified, assuming up to but not including the next major release) IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.5
Description The issue concerns a default administrator account that is enabled when the IPMI LAN channel is enabled, allowing a remote attacker to gain unauthorized access to the BMC.
Recommendations For IBM DataPower Gateway versions 6.0.0 through 6.0.14, disable the default administrator account or restrict access to the IPMI LAN channel. For IBM DataPower Gateway versions 7.6.0.0, disable the default administrator account or restrict access to the IPMI LAN channel. For IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.5, disable the default administrator account or restrict access to the IPMI LAN channel.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-4621

Affected Products

Ibm Datapower Gateway