ID

VAR-201212-0207


CVE

CVE-2012-4856


TITLE

IBM Power 5 Service Processor privilege escalation vulnerability

Trust: 0.8

sources: CERT/CC: VU#194604

DESCRIPTION

The Service Processor in the IBM Power 5 91##-### and 940#-### before SF240_418_382 does not ensure that firewall code is executed, which allows remote attackers to execute arbitrary code via unspecified vectors. IBM Server Firmware Power 5 is prone to a remote privilege-escalation vulnerability. Attackers can exploit this issue to gain unauthorized administrative access to the affected device. This may aid in further attacks

Trust: 2.7

sources: NVD: CVE-2012-4856 // CERT/CC: VU#194604 // JVNDB: JVNDB-2012-005719 // BID: 56910 // VULHUB: VHN-58137

AFFECTED PRODUCTS

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_233_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_258_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_284_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_201_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_219_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_222_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_261_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_338_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_202_201

Trust: 1.6

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_259_201

Trust: 1.6

vendor:ibmmodel:power 5scope:eqversion:9113-550

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9406-525

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9110-51a

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_332_201

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_358_201

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9406-570

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_299_201

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_417

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9117-570

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9131-52a

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9405-520

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9115-505

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9406-520

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_403_382

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_371

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_298_201

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:lteversion:sf240_418

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9116-561

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9407-515

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_382_382

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9124-720

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9118-575

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_415_382

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9111-285

Trust: 1.0

vendor:ibmmodel:power 5 systemscope:eqversion:sf240_320_201

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9133-55a

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9123-710

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9406-550

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9110-510

Trust: 1.0

vendor:ibmmodel:power 5scope:eqversion:9111-520

Trust: 1.0

vendor:ibmmodel: - scope: - version: -

Trust: 0.8

vendor:ibmmodel:power 5scope:eqversion:specific products with

Trust: 0.8

vendor:ibmmodel:power 5 systemscope:ltversion:sf240_418_382

Trust: 0.8

sources: CERT/CC: VU#194604 // JVNDB: JVNDB-2012-005719 // CNNVD: CNNVD-201212-185 // NVD: CVE-2012-4856

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2012-4856
value: HIGH

Trust: 1.6

nvd@nist.gov: CVE-2012-4856
value: HIGH

Trust: 1.0

CNNVD: CNNVD-201212-185
value: HIGH

Trust: 0.6

VULHUB: VHN-58137
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2012-4856
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

NVD: CVE-2012-4856
severity: HIGH
baseScore: 7.9
vectorString: NONE
accessVector: ADJACENT NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.8

VULHUB: VHN-58137
severity: HIGH
baseScore: 7.9
vectorString: AV:A/AC:M/AU:N/C:C/I:C/A:C
accessVector: ADJACENT_NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 5.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: CERT/CC: VU#194604 // VULHUB: VHN-58137 // JVNDB: JVNDB-2012-005719 // CNNVD: CNNVD-201212-185 // NVD: CVE-2012-4856

PROBLEMTYPE DATA

problemtype:CWE-255

Trust: 1.9

sources: VULHUB: VHN-58137 // JVNDB: JVNDB-2012-005719 // NVD: CVE-2012-4856

THREAT TYPE

specific network environment

Trust: 0.6

sources: CNNVD: CNNVD-201212-185

TYPE

trust management

Trust: 0.6

sources: CNNVD: CNNVD-201212-185

CONFIGURATIONS

sources: JVNDB: JVNDB-2012-005719

EXPLOIT AVAILABILITY

sources: CERT/CC: VU#194604

PATCH

title:Security Vulnerability in Select IBM Power 5 Systems - Service Processorurl:http://aix.software.ibm.com/aix/efixes/security/squadrons_advisory.asc

Trust: 0.8

title:Fix Centralurl:http://www-933.ibm.com/support/fixcentral/

Trust: 0.8

title:01SF240_418_382url:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=45199

Trust: 0.6

sources: JVNDB: JVNDB-2012-005719 // CNNVD: CNNVD-201212-185

EXTERNAL IDS

db:CERT/CCid:VU#194604

Trust: 3.6

db:NVDid:CVE-2012-4856

Trust: 2.8

db:BIDid:56910

Trust: 1.0

db:JVNid:JVNVU99536825

Trust: 0.8

db:JVNDBid:JVNDB-2012-005719

Trust: 0.8

db:CNNVDid:CNNVD-201212-185

Trust: 0.7

db:XFid:79736

Trust: 0.6

db:VULHUBid:VHN-58137

Trust: 0.1

sources: CERT/CC: VU#194604 // VULHUB: VHN-58137 // BID: 56910 // JVNDB: JVNDB-2012-005719 // CNNVD: CNNVD-201212-185 // NVD: CVE-2012-4856

REFERENCES

url:http://aix.software.ibm.com/aix/efixes/security/squadrons_advisory.asc

Trust: 2.8

url:http://www.kb.cert.org/vuls/id/194604

Trust: 2.8

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/79736

Trust: 1.1

url:about vulnerability notes

Trust: 0.8

url:contact us about this vulnerability

Trust: 0.8

url:provide a vendor statement

Trust: 0.8

url:https://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2012-4856

Trust: 0.8

url:http://jvn.jp/cert/jvnvu99536825/index.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2012-4856

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/79736

Trust: 0.6

url:http://www.securityfocus.com/bid/56910

Trust: 0.6

sources: CERT/CC: VU#194604 // VULHUB: VHN-58137 // BID: 56910 // JVNDB: JVNDB-2012-005719 // CNNVD: CNNVD-201212-185 // NVD: CVE-2012-4856

CREDITS

Brian Smith

Trust: 0.9

sources: BID: 56910 // CNNVD: CNNVD-201212-185

SOURCES

db:CERT/CCid:VU#194604
db:VULHUBid:VHN-58137
db:BIDid:56910
db:JVNDBid:JVNDB-2012-005719
db:CNNVDid:CNNVD-201212-185
db:NVDid:CVE-2012-4856

LAST UPDATE DATE

2025-04-11T23:14:44.342000+00:00


SOURCES UPDATE DATE

db:CERT/CCid:VU#194604date:2013-01-02T00:00:00
db:VULHUBid:VHN-58137date:2017-08-29T00:00:00
db:BIDid:56910date:2012-12-12T00:00:00
db:JVNDBid:JVNDB-2012-005719date:2012-12-21T00:00:00
db:CNNVDid:CNNVD-201212-185date:2012-12-21T00:00:00
db:NVDid:CVE-2012-4856date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:CERT/CCid:VU#194604date:2012-12-12T00:00:00
db:VULHUBid:VHN-58137date:2012-12-20T00:00:00
db:BIDid:56910date:2012-12-12T00:00:00
db:JVNDBid:JVNDB-2012-005719date:2012-12-14T00:00:00
db:CNNVDid:CNNVD-201212-185date:2012-12-14T00:00:00
db:NVDid:CVE-2012-4856date:2012-12-20T12:02:18.200