CVE Feed

    Dashboard / CVE / CVE-2013-4037

    CVE-2013-4037

    The RAKP protocol support in the Intelligent Platform Management Interface (IPMI) implementation in Integrated Management Module (IMM) and Integrated Management Module II (IMM2) on IBM BladeCenter, Flex System, System x iDataPlex, and System x3### servers sends a password hash to the client, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Published:Aug 9, 2013
    Last Modified:Apr 11, 2025
    EPS:Aug 9, 2013
    EPSS Score:0.00218
    CVSS Score:4.3

    Affected Products

    Vendor
    Ibm
    Product
    Bladecenter
    Vendor
    Ibm
    Product
    Flex System X220 Compute Node
    Vendor
    Ibm
    Product
    Flex System X240 Compute Node
    Vendor
    Ibm
    Product
    Flex System X440 Compute Node
    Vendor
    Ibm
    Product
    System X3100 M4
    Vendor
    Ibm
    Product
    System X3200 M3
    Vendor
    Ibm
    Product
    System X3250 M3
    Vendor
    Ibm
    Product
    System X3250 M4
    Vendor
    Ibm
    Product
    System X3400 M2
    Vendor
    Ibm
    Product
    System X3400 M3
    Vendor
    Ibm
    Product
    System X3500 M2
    Vendor
    Ibm
    Product
    System X3500 M3
    Vendor
    Ibm
    Product
    System X3500 M4
    Vendor
    Ibm
    Product
    System X3530 M4
    Vendor
    Ibm
    Product
    System X3550 M2
    Vendor
    Ibm
    Product
    System X3550 M3
    Vendor
    Ibm
    Product
    System X3550 M4
    Vendor
    Ibm
    Product
    System X3620 M3
    Vendor
    Ibm
    Product
    System X3630 M3
    Vendor
    Ibm
    Product
    System X3630 M4
    Vendor
    Ibm
    Product
    System X3650 M2
    Vendor
    Ibm
    Product
    System X3650 M3
    Vendor
    Ibm
    Product
    System X3650 M4
    Vendor
    Ibm
    Product
    System X3690 X5
    Vendor
    Ibm
    Product
    System X3750 M4
    Vendor
    Ibm
    Product
    System X3850 X5
    Vendor
    Ibm
    Product
    System X3950 X5
    Vendor
    Ibm
    Product
    System X Idataplex Dx360 M2 Server
    Vendor
    Ibm
    Product
    System X Idataplex Dx360 M3 Server
    Vendor
    Ibm
    Product
    System X Idataplex Dx360 M4 Server

    Exploits

    No exploit reference

    Common Weakness Enumeration

    No CWE recorded yet

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High