CVE-2019-4169
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: NVD
Description
IBM Open Power Firmware OP910 and OP920 could allow access to BMC via IPMI using default OpenBMC password even after BMC password was changed away from the default password. IBM X-Force ID: 158702.
Affected (2)
Products: Ibm: Open Power
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version op910 |
| Running on/with | Platform Versions |
|---|---|
Ibm Power System 8335 Gth | All versions |
Ibm Power System 8335 Gtx | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version op920 |
| Running on/with | Platform Versions |
|---|---|
Ibm Power System 8335 Gtc | All versions |
Ibm Power System 8335 Gtg | All versions |
Ibm Power System 8335 Gtw | All versions |
References (4)
Source: psirt@us.ibm.com
VDB EntryVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
VDB EntryVendor Advisory
Timeline
No history available yet.