CVE-2004-2600

Description

The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled.

Risk Information

Base Score
5.3
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Score
Exploitation Probability
1.141

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2004-2600 are affected in carrier_grade_server_cc2300 a6899aNCM
Vulnerabilities CVE-2004-2600 are affected in carrier_grade_server_cc2300 a6898aNCM
Vulnerabilities CVE-2004-2600 are affected in carrier_grade_server_cc3300 a6901aNCM
Vulnerabilities CVE-2004-2600 are affected in carrier_grade_server_cc3300 a6900aNCM
Vulnerabilities CVE-2004-2600 are affected in carrier_grade_server_cc3310 a9863aNCM
Vulnerabilities CVE-2004-2600 are affected in carrier_grade_server_cc3310 a9862aNCM
CVE-2004-2600NCM

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234