ID

VAR-200706-0340


CVE

CVE-2007-2387


TITLE

Intel On hardware Apple Xserve Lights-Out Management Vulnerabilities that gain management access

Trust: 0.8

sources: JVNDB: JVNDB-2007-001936

DESCRIPTION

Apple Xserve Lights-Out Management before Firmware Update 1.0 on Intel hardware does not require a password for remote access to IPMI, which allows remote attackers to gain administrative access via unspecified requests with ipmitool. This issue affects Intel-based Xservers running Lights-Out Management Firmware configured in a particular manner. Xserve is a high-performance server launched by Apple

Trust: 1.98

sources: NVD: CVE-2007-2387 // JVNDB: JVNDB-2007-001936 // BID: 24257 // VULHUB: VHN-25749

AFFECTED PRODUCTS

vendor:applemodel:xserve lights-out managementscope:eqversion:firmware_0

Trust: 1.6

vendor:applemodel:xserve lights-out managementscope:ltversion:firmware update 1.0

Trust: 0.8

vendor:applemodel:xserve lights-out managementscope:eqversion:0

Trust: 0.3

sources: BID: 24257 // JVNDB: JVNDB-2007-001936 // CNNVD: CNNVD-200706-019 // NVD: CVE-2007-2387

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2007-2387
value: HIGH

Trust: 1.0

NVD: CVE-2007-2387
value: HIGH

Trust: 0.8

CNNVD: CNNVD-200706-019
value: CRITICAL

Trust: 0.6

VULHUB: VHN-25749
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2007-2387
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-25749
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-25749 // JVNDB: JVNDB-2007-001936 // CNNVD: CNNVD-200706-019 // NVD: CVE-2007-2387

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2007-2387

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200706-019

TYPE

Boundary Condition Error

Trust: 0.9

sources: BID: 24257 // CNNVD: CNNVD-200706-019

CONFIGURATIONS

sources: JVNDB: JVNDB-2007-001936

PATCH

title:APPLE-SA-2007-05-31url:http://lists.apple.com/archives/security-announce/2007/May/msg00006.html

Trust: 0.8

sources: JVNDB: JVNDB-2007-001936

EXTERNAL IDS

db:NVDid:CVE-2007-2387

Trust: 2.8

db:BIDid:24257

Trust: 2.0

db:SECTRACKid:1018181

Trust: 1.7

db:VUPENid:ADV-2007-2014

Trust: 1.7

db:SECUNIAid:25499

Trust: 1.7

db:OSVDBid:36128

Trust: 1.7

db:JVNDBid:JVNDB-2007-001936

Trust: 0.8

db:CNNVDid:CNNVD-200706-019

Trust: 0.7

db:APPLEid:APPLE-SA-2007-05-31

Trust: 0.6

db:XFid:34651

Trust: 0.6

db:VULHUBid:VHN-25749

Trust: 0.1

sources: VULHUB: VHN-25749 // BID: 24257 // JVNDB: JVNDB-2007-001936 // CNNVD: CNNVD-200706-019 // NVD: CVE-2007-2387

REFERENCES

url:http://docs.info.apple.com/article.html?artnum=305571

Trust: 2.0

url:http://lists.apple.com/archives/security-announce/2007/may/msg00006.html

Trust: 1.7

url:http://www.securityfocus.com/bid/24257

Trust: 1.7

url:http://www.apple.com/support/downloads/xservelightsoutmanagementfirmwareupdate10.html

Trust: 1.7

url:http://osvdb.org/36128

Trust: 1.7

url:http://www.securitytracker.com/id?1018181

Trust: 1.7

url:http://secunia.com/advisories/25499

Trust: 1.7

url:http://www.vupen.com/english/advisories/2007/2014

Trust: 1.1

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/34651

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2007-2387

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2007-2387

Trust: 0.8

url:http://www.frsirt.com/english/advisories/2007/2014

Trust: 0.6

url:http://xforce.iss.net/xforce/xfdb/34651

Trust: 0.6

url:http://www.apple.com/xserve/

Trust: 0.3

sources: VULHUB: VHN-25749 // BID: 24257 // JVNDB: JVNDB-2007-001936 // CNNVD: CNNVD-200706-019 // NVD: CVE-2007-2387

CREDITS

James Wilson

Trust: 0.6

sources: CNNVD: CNNVD-200706-019

SOURCES

db:VULHUBid:VHN-25749
db:BIDid:24257
db:JVNDBid:JVNDB-2007-001936
db:CNNVDid:CNNVD-200706-019
db:NVDid:CVE-2007-2387

LAST UPDATE DATE

2025-04-10T23:11:36.702000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-25749date:2017-07-29T00:00:00
db:BIDid:24257date:2007-06-01T16:31:00
db:JVNDBid:JVNDB-2007-001936date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200706-019date:2007-06-05T00:00:00
db:NVDid:CVE-2007-2387date:2025-04-09T00:30:58.490

SOURCES RELEASE DATE

db:VULHUBid:VHN-25749date:2007-06-04T00:00:00
db:BIDid:24257date:2007-05-31T00:00:00
db:JVNDBid:JVNDB-2007-001936date:2012-06-26T00:00:00
db:CNNVDid:CNNVD-200706-019date:2007-05-31T00:00:00
db:NVDid:CVE-2007-2387date:2007-06-04T17:30:00