UNSOLVED

Eric87

updated

13 years ago

E

Eric87

1 Message

0

55238

July 29th, 2013 09:00

IDRAC6 IPMI 2.0 Cipher Type Zero Authentication Bypass Vulnerability

We have a R610 server with a IDRAC6 Monolithic interface at version 1.95. The below IDRAC6 vulnerability was recently identified. Is anyone aware of any plans to patch the below vulnerability on the IDRAC6 Monolithic?

IDRAC6 Home Page: http://en.community.dell.com/techcenter/systems-management/w/wiki/4357.idrac6-home.aspx#exe_summary

Vulnerability Name:  IPMI 2.0 Cipher Type Zero Authentication Bypass Vulnerability

Vulnerability Description:   The IPMI 2.0 specification supports a cipher with identifier 0. Many vendors have implemented this cipher, which allows for complete bypass of the IPMI authentication process.

URL: removed

Thank you for reviewing this post.

Eric