PT-2019-17143 · Ibm · Ibm Datapower Gateway
Published
2019-12-09
·
Updated
2019-12-17
·
CVE-2019-4621
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
IBM DataPower Gateway versions 6.0.0 through 6.0.14
IBM DataPower Gateway versions 7.6.0.0 through 7.6.0 (no end version specified, assuming up to but not including the next major release)
IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.5
Description
The issue concerns a default administrator account that is enabled when the IPMI LAN channel is enabled, allowing a remote attacker to gain unauthorized access to the BMC.
Recommendations
For IBM DataPower Gateway versions 6.0.0 through 6.0.14, disable the default administrator account or restrict access to the IPMI LAN channel.
For IBM DataPower Gateway versions 7.6.0.0, disable the default administrator account or restrict access to the IPMI LAN channel.
For IBM DataPower Gateway versions 2018.4.1.0 through 2018.4.1.5, disable the default administrator account or restrict access to the IPMI LAN channel.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ibm Datapower Gateway