CVE-2013-4030
Severity CVSS v4.0:
Pending analysis
Type:
CWE-310
Cryptographic Issues
Publication date:
21/01/2014
Last modified:
11/04/2025
Description
Integrated Management Module (IMM) 2 1.00 through 2.00 on IBM System X and Flex System servers supports SSL cipher suites with short keys, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack against (1) SSL or (2) TLS traffic.
Impact
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:h:ibm:integrated_management_module_2:1.00:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:integrated_management_module_2:2.00:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:bladecenter:hs23:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:bladecenter:hs23e:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:flex_system_manager_node_7955:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:flex_system_manager_node_8731:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:flex_system_manager_node_8734:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:flex_system_x220_compute_node:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:flex_system_x240_compute_node:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:flex_system_x440_compute_node:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:system_x_idataplex_direct_water_cooled_dx360_m4_server:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:system_x_idataplex_dx360_m4_server:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:system_x3100_m4:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:system_x3250_m4:-:*:*:*:*:*:*:* | ||
cpe:2.3:h:ibm:system_x3300_m4:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_avoiding_weak_ssl_tls_encryption_in_ibm_system_x_and_flex_systems_cve_2013_40301
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86068
- http://www.ibm.com/connections/blogs/PSIRT/entry/security_bulletin_avoiding_weak_ssl_tls_encryption_in_ibm_system_x_and_flex_systems_cve_2013_40301
- https://exchange.xforce.ibmcloud.com/vulnerabilities/86068