ID

VAR-201409-0076


CVE

CVE-2014-4752


TITLE

plural IBM Vulnerability to obtain access rights in products

Trust: 0.8

sources: JVNDB: JVNDB-2014-004408

DESCRIPTION

IBM System Networking G8052, G8124, G8124-E, G8124-ER, G8264, G8316, and G8264-T switches before 7.9.10.0; EN4093, EN4093R, CN4093, SI4093, EN2092, and G8264CS switches before 7.8.6.0; Flex System Interconnect Fabric before 7.8.6.0; 1G L2-7 SLB switch for Bladecenter before 21.0.21.0; 10G VFSM for Bladecenter before 7.8.14.0; 1:10G switch for Bladecenter before 7.4.8.0; 1G switch for Bladecenter before 5.3.5.0; Server Connectivity Module before 1.1.3.4; System Networking RackSwitch G8332 before 7.7.17.0; and System Networking RackSwitch G8000 before 7.1.7.0 have hardcoded credentials, which makes it easier for remote attackers to obtain access via unspecified vectors. IBM System Networking , Flex System Interconnect Fabric And other IBM Since the product has hard-coded authentication information, there is a vulnerability that can gain access. Supplementary information : CWE Vulnerability type by CWE-798: Use of Hard-coded Credentials ( Using hard-coded credentials ) Has been identified. http://cwe.mitre.org/data/definitions/798.htmlAccess may be obtained by a third party. An attacker can exploit this issue to bypass the authentication mechanism and gain unauthorized access to the affected device. This may aid in further attacks. The following products and versions are affected: IBM System Networking G8052, G8124, G8124-E, G8124-ER, G8264, G8316, G8264-T switches versions prior to 7.9.10.0; EN4093, EN4093R, CN4093, SI4093, EN2092, G8264CS switches 7.8

Trust: 1.98

sources: NVD: CVE-2014-4752 // JVNDB: JVNDB-2014-004408 // BID: 69968 // VULHUB: VHN-72693

AFFECTED PRODUCTS

vendor:ibmmodel:bladecenter 1\/10gscope:lteversion:7.4.7.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8264tscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8264scope:lteversion:7.9.1.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8316scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:bladecenter 1gscope:lteversion:5.3.4.0

Trust: 1.0

vendor:ibmmodel:flex system interconnect fabricscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch en2092scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch en2092scope:lteversion:7.8.5.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch si4093scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch cn4093scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8124erscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8332scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8316scope:lteversion:7.9.1.0

Trust: 1.0

vendor:ibmmodel:bladecenter 1gscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:bladecenter 10g vfsmscope:lteversion:7.8.6.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch en4093rscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:server connectivity modulescope:lteversion:1.1.3.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8052scope:lteversion:7.9.1.0

Trust: 1.0

vendor:ibmmodel:bladecenter 1g l2-7 slbscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch en4093scope:lteversion:7.8.5.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8124scope:lteversion:7.9.1.0

Trust: 1.0

vendor:ibmmodel:flex system interconnect fabricscope:lteversion:7.8.5.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8264scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8124erscope:lteversion:7.9.1.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8052scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:bladecenter 1g l2-7 slbscope:lteversion:21.0.20.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch en4093rscope:lteversion:7.8.5.0

Trust: 1.0

vendor:ibmmodel:bladecenter 10g vfsmscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8332scope:lteversion:7.7.16.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8124escope:lteversion:7.9.1.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8264tscope:lteversion:7.9.1.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8124escope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch en4093scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8124scope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch si4093scope:lteversion:7.8.5.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8332scope:lteversion:7.1.6.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8264csscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:server connectivity modulescope:eqversion: -

Trust: 1.0

vendor:ibmmodel:bladecenter 1\/10gscope:eqversion: -

Trust: 1.0

vendor:ibmmodel:system networking rackswitch cn4093scope:lteversion:7.8.5.0

Trust: 1.0

vendor:ibmmodel:system networking rackswitch g8264csscope:lteversion:7.8.5.0

Trust: 1.0

vendor:ibmmodel:1g l2-7 slb switch for bladecenterscope: - version: -

Trust: 0.8

vendor:ibmmodel:1g l2-7 slb switch for bladecenterscope:ltversion:21.0.21.0

Trust: 0.8

vendor:ibmmodel:1g switch for bladecenterscope: - version: -

Trust: 0.8

vendor:ibmmodel:1g switch for bladecenterscope:ltversion:5.3.5.0

Trust: 0.8

vendor:ibmmodel:bladecenter 1/10g uplink ethernet switch modulescope: - version: -

Trust: 0.8

vendor:ibmmodel:bladecenter 1/10g uplink ethernet switch modulescope:ltversion:7.4.8.0

Trust: 0.8

vendor:ibmmodel:bladecenter server connectivity modulescope: - version: -

Trust: 0.8

vendor:ibmmodel:bladecenter server connectivity modulescope:ltversion:1.1.3.4

Trust: 0.8

vendor:ibmmodel:flex system en2092 1gb ethernet scalable switchscope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system en2092 1gb ethernet scalable switchscope:ltversion:7.8.6.0

Trust: 0.8

vendor:ibmmodel:flex system fabric cn4093 10gb converged scalable switchscope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system fabric cn4093 10gb converged scalable switchscope:ltversion:7.8.6.0

Trust: 0.8

vendor:ibmmodel:flex system fabric en4093 10gb scalable switchscope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system fabric en4093 10gb scalable switchscope:ltversion:7.8.6.0

Trust: 0.8

vendor:ibmmodel:flex system fabric en4093r 10gb scalable switchscope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system fabric en4093r 10gb scalable switchscope:ltversion:7.8.6.0

Trust: 0.8

vendor:ibmmodel:flex system fabric si4093 system interconnect modulescope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system fabric si4093 system interconnect modulescope:ltversion:7.8.6.0

Trust: 0.8

vendor:ibmmodel:flex system interconnect fabricscope: - version: -

Trust: 0.8

vendor:ibmmodel:flex system interconnect fabricscope:ltversion:21.0.21.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8000scope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8000scope:ltversion:7.1.7.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8052scope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8052scope:ltversion:7.9.10.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8124scope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8124scope:ltversion:7.9.10.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8124escope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8124escope:ltversion:7.9.10.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8124erscope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8124erscope:ltversion:7.9.10.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8264scope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8264scope:ltversion:7.9.10.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8264csscope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8264csscope:ltversion:7.8.6.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8264tscope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8264tscope:ltversion:7.9.10.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8316scope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8316scope:ltversion:7.9.10.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8332scope: - version: -

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8332scope:ltversion:7.7.17.0

Trust: 0.8

vendor:ibmmodel:virtual fabric 10gb switch module for ibm bladecenterscope: - version: -

Trust: 0.8

vendor:ibmmodel:virtual fabric 10gb switch module for ibm bladecenterscope:ltversion:7.8.14.0

Trust: 0.8

vendor:ibmmodel:system networking rackswitch g8124escope:eqversion:7.9.1.0

Trust: 0.6

vendor:ibmmodel:system networking rackswitch si4093scope:eqversion:7.8.5.0

Trust: 0.6

vendor:ibmmodel:system networking rackswitch g8316scope:eqversion:7.9.1.0

Trust: 0.6

vendor:ibmmodel:system networking rackswitch g8264scope:eqversion:7.9.1.0

Trust: 0.6

vendor:ibmmodel:system networking rackswitch g8124scope:eqversion:7.9.1.0

Trust: 0.6

vendor:ibmmodel:bladecenter 1\/10gscope:eqversion:7.4.7.0

Trust: 0.6

vendor:ibmmodel:system networking rackswitch g8264tscope:eqversion:7.9.1.0

Trust: 0.6

vendor:ibmmodel:flex system interconnect fabricscope:eqversion:7.8.5.0

Trust: 0.6

vendor:ibmmodel:system networking rackswitch g8124erscope:eqversion:7.9.1.0

Trust: 0.6

vendor:ibmmodel:bladecenter 1g l2-7 slbscope:eqversion:21.0.20.0

Trust: 0.6

vendor:ibmmodel:system networking rackswitch g8332scope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8316scope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8264csscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8264-tscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8264scope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8124-erscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8124-escope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8124scope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8052scope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8000scope:eqversion:0

Trust: 0.3

vendor:ibmmodel:server connectivity modulescope:eqversion:0

Trust: 0.3

vendor:ibmmodel:flex system interconnect fabricscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:flex system fabric si4093 system interconnect modulescope:eqversion:0

Trust: 0.3

vendor:ibmmodel:flex system fabric en4093r 10gb scalable switchscope:eqversion:7.8.4.0

Trust: 0.3

vendor:ibmmodel:flex system fabric en4093 10gb scalable switchscope:eqversion:7.8.4.0

Trust: 0.3

vendor:ibmmodel:flex system fabric cn4093 10gb converged scalable switchscope:eqversion:7.8.4.0

Trust: 0.3

vendor:ibmmodel:flex system en2092 1gb ethernet scalable switchscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:1g switch for bladecenterscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:10g vfsm for bladecenterscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:1:10g switch for bladecenterscope:eqversion:0

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8332scope:neversion:7.7.170

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8316scope:neversion:7.9.100

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8264csscope:neversion:7.8.60

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8264-tscope:neversion:7.9.100

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8264scope:neversion:7.9.100

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8124-erscope:neversion:7.9.100

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8124-escope:neversion:7.9.100

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8124scope:neversion:7.9.100

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8052scope:neversion:7.9.100

Trust: 0.3

vendor:ibmmodel:system networking rackswitch g8000scope:neversion:7.1.70

Trust: 0.3

vendor:ibmmodel:server connectivity modulescope:neversion:1.1.34

Trust: 0.3

vendor:ibmmodel:flex system interconnect fabricscope:neversion:21.0.210

Trust: 0.3

vendor:ibmmodel:flex system fabric si4093 system interconnect modulescope:neversion:7.8.60

Trust: 0.3

vendor:ibmmodel:flex system fabric en4093r 10gb scalable switchscope:neversion:7.8.6.0

Trust: 0.3

vendor:ibmmodel:flex system fabric en4093 10gb scalable switchscope:neversion:7.8.6.0

Trust: 0.3

vendor:ibmmodel:flex system en2092 1gb ethernet scalable switchscope:neversion:7.8.60

Trust: 0.3

vendor:ibmmodel:1g switch for bladecenterscope:neversion:5.3.50

Trust: 0.3

vendor:ibmmodel:10g vfsm for bladecenterscope:neversion:7.8.140

Trust: 0.3

vendor:ibmmodel:1:10g switch for bladecenterscope:neversion:7.4.80

Trust: 0.3

sources: BID: 69968 // JVNDB: JVNDB-2014-004408 // CNNVD: CNNVD-201409-889 // NVD: CVE-2014-4752

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2014-4752
value: HIGH

Trust: 1.0

NVD: CVE-2014-4752
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201409-889
value: CRITICAL

Trust: 0.6

VULHUB: VHN-72693
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2014-4752
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-72693
severity: HIGH
baseScore: 10.0
vectorString: AV:N/AC:L/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 10.0
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-72693 // JVNDB: JVNDB-2014-004408 // CNNVD: CNNVD-201409-889 // NVD: CVE-2014-4752

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2014-004408 // NVD: CVE-2014-4752

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201409-889

TYPE

Design Error

Trust: 0.3

sources: BID: 69968

CONFIGURATIONS

sources: JVNDB: JVNDB-2014-004408

PATCH

title:Backdoor Access Vulnerability in IBM System Networking Products (CVE- 2014-4752)url:http://www.ibm.com/support/entry/portal/docdisplay?lndocid=MIGR-5096232

Trust: 0.8

sources: JVNDB: JVNDB-2014-004408

EXTERNAL IDS

db:NVDid:CVE-2014-4752

Trust: 2.8

db:SECUNIAid:54512

Trust: 1.1

db:JVNDBid:JVNDB-2014-004408

Trust: 0.8

db:CNNVDid:CNNVD-201409-889

Trust: 0.7

db:BIDid:69968

Trust: 0.4

db:VULHUBid:VHN-72693

Trust: 0.1

sources: VULHUB: VHN-72693 // BID: 69968 // JVNDB: JVNDB-2014-004408 // CNNVD: CNNVD-201409-889 // NVD: CVE-2014-4752

REFERENCES

url:http://www.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5096232

Trust: 1.7

url:http://secunia.com/advisories/54512

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2014-4752

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2014-4752

Trust: 0.8

url:http://www.ibm.com

Trust: 0.3

url:http://www-947.ibm.com/support/entry/portal/docdisplay?lndocid=migr-5096232

Trust: 0.3

sources: VULHUB: VHN-72693 // BID: 69968 // JVNDB: JVNDB-2014-004408 // CNNVD: CNNVD-201409-889 // NVD: CVE-2014-4752

CREDITS

IBM

Trust: 0.3

sources: BID: 69968

SOURCES

db:VULHUBid:VHN-72693
db:BIDid:69968
db:JVNDBid:JVNDB-2014-004408
db:CNNVDid:CNNVD-201409-889
db:NVDid:CVE-2014-4752

LAST UPDATE DATE

2025-04-13T23:04:50.343000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-72693date:2015-11-27T00:00:00
db:BIDid:69968date:2014-08-07T00:00:00
db:JVNDBid:JVNDB-2014-004408date:2014-09-26T00:00:00
db:CNNVDid:CNNVD-201409-889date:2014-09-24T00:00:00
db:NVDid:CVE-2014-4752date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-72693date:2014-09-23T00:00:00
db:BIDid:69968date:2014-08-07T00:00:00
db:JVNDBid:JVNDB-2014-004408date:2014-09-26T00:00:00
db:CNNVDid:CNNVD-201409-889date:2014-09-24T00:00:00
db:NVDid:CVE-2014-4752date:2014-09-23T22:55:03.653